Intel

AIKIDO-2026-980131

external-workspace-manager is vulnerable to Missing Authorization

Missing AuthorizationCVE-2026-70436 Published 3 days ago

43

Medium Risk

This Affects:

JAVAexternal-workspace-manager
0.0.1 - 1.4.1
Fixed in 1.4.2
Are you affected? Scan for Free

TL;DR

The workspace browser skips or incorrectly applies permission checks for externally managed workspaces. An attacker with Overall/Read permission can read workspace files they should not access. The fix performs the expected permission check before serving those workspaces.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range and use externally managed workspaces browsable through the plugin.

Background info

external-workspace-manager is vulnerable to Missing Authorization in versions 0.0.1 - 1.4.1.

How to fix this

Upgrade the org.jenkins-ci.plugins:external-workspace-manager library to the patch version.