CVE-2019-10377
07.08.2019, 15:15
A missing permission check in Jenkins Avatar Plugin 1.2 and earlier allows attackers with Overall/Read access to change the avatar of any user of Jenkins.Enginsight
Vendor | Product | Version |
---|---|---|
jenkins | avatar | 𝑥 ≤ 1.2 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration