-
CVSS Score
-The commit diff shows these three form validation methods (doCheckUrl, doLoginCheck, doOldLoginCheck) in IceScrumProjectProperty.java lacked Jenkins.ADMINISTER permission checks prior to patching. These methods handle URL validation and credential verification, and the vulnerability description explicitly states attackers with Overall/Read could exploit them. The patch adds explicit checkPermission() calls, confirming these were the missing authorization points.
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| org.jenkins-ci.plugins:icescrum | maven | < 1.1.6 | 1.1.6 |
A Semantic Attack on Google Gemini - Read the Latest Research