appscan is vulnerable to Missing Authorization
43
Medium Risk
Several HTTP endpoints skip permission checks. An attacker with Overall/Read permission can list credentials IDs stored in Jenkins, which can help capture those credentials when combined with another issue. The fix requires appropriate permissions on the affected endpoints.
You are affected if you are using a version that falls within the vulnerable range and users with Overall/Read permission can reach the plugin HTTP endpoints.
appscan is vulnerable to Missing Authorization in versions 0.0.1 - 1.8.3.
Upgrade the com.hcl.security:appscan library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant