-
CVSS Score
-The vulnerability stems from the doValidate method in JiraSite.java, which handled form validation without adequate permission checks. The commit diff shows the addition of @RequirePOST annotation and permission checks (Jenkins.ADMINISTER or Item.CONFIGURE) in this method. The security tests added in JiraSiteSecurity1029Test.java specifically validate() these authorization improvements, confirming this was the attack surface.
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| org.jenkins-ci.plugins:jira | maven | <= 3.0.1 | 3.0.2 |
A Semantic Attack on Google Gemini - Read the Latest Research