A missing permission check in Jenkins MongoDB Plugin 1.3 and earlier allows attackers with Overall/Read permission to gain access to some metadata of any arbitrary files on the Jenkins controller.
References:GSA_kwCzR0hTQS1jMjZoLThoNHAtNGpnas4AAl83
Missing permission checks in MongoDB Plugin
| Affected Packages | Affected Versions | Fixed Versions | |
|---|---|---|---|
| maven:org.jenkins-ci.plugins:mongodb | <= 1.3 | No known fixed version | |
|
|
|||