VulnerabilityModified
CVE-2013-6373
The Exclusion plugin before 0.9 for Jenkins does not properly prevent access to resource locks, which allows remote authenticated users to list and release resources via unspecified vectors.
MEDIUM 5.5EPSS 1.15%
Does this matter?
Lower severity and a low EPSS score (1.15%). Track it; it rarely justifies an emergency change on its own.
Description
The Exclusion plugin before 0.9 for Jenkins does not properly prevent access to resource locks, which allows remote authenticated users to list and release resources via unspecified vectors.
- CVSS 2.0
- 5.5 MEDIUMAV:N/AC:L/Au:S/C:P/I:N/A:P
- EPSS
- 1.15% probability · 65th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-264
- Affected
- jenkins-ci/exclusion
- Source
- secalert@redhat.com
References
- https://wiki.jenkins-ci.org/display/JENKINS/Exclusion-Plugin
- https://wiki.jenkins-ci.org/display/SECURITY/Jenkins+Security+Advisory+2013-11-20Vendor Advisory
- https://wiki.jenkins-ci.org/display/JENKINS/Exclusion-Plugin
- https://wiki.jenkins-ci.org/display/SECURITY/Jenkins+Security+Advisory+2013-11-20Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.