The Exclusion plugin before 0.9 for Jenkins does not properly prevent access to resource locks, which allows remote authenticated users to list and release resources via unspecified vectors.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Exclusion | Jenkins-ci | * | 0.8 (including) |
Exclusion | Jenkins-ci | 0.6 (including) | 0.6 (including) |
Exclusion | Jenkins-ci | 0.7 (including) | 0.7 (including) |