script-security is vulnerable to Improper Access Control
43
Medium Risk
A constructor annotated with @DataBoundConstructor loads script approval configuration through Stapler data binding. Attackers able to submit certain forms can invoke that path and read script approval configuration that should not be exposed. The fix removes the @DataBoundConstructor annotation from that constructor.
You are affected if you are using a version that falls within the vulnerable range and users can submit forms that bind Script Security plugin configuration.
script-security is vulnerable to Improper Access Control in versions 0.0.1 - 1412.
Upgrade the org.jenkins-ci.plugins:script-security library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.