A missing permission check in Jenkins AWS Global Configuration Plugin 1.5 and earlier allows attackers with Overall/Read permission to replace the global AWS configuration.
Affected Software
Name |
Vendor |
Start Version |
End Version |
Aws_global_configuration |
Jenkins |
* |
1.5 (including) |
References