MEDIUM
A missing permission check in Jenkins Avatar Plugin 1.2 and earlier allows attackers with Overall/Read access to change the avatar of any user of Jenkins
Published Aug 7, 2019
4.3
MEDIUMCVSS 3.1
EPSS 0.69%
Description
Affected products
Remediation
References (5)
Change history (0)
No recorded changes yet.