-
CVSS Score
-The vulnerability description explicitly mentions a missing permission check in a form validation method. Jenkins plugin security patterns indicate that form validation methods in Descriptor classes (typically named doValidate*) are common locations for such vulnerabilities. The fix adding POST enforcement and Administer permission requirements confirms this was likely a form validation handler for NS-ND credentials/server configuration. The function name and class structure are inferred from standard Jenkins plugin conventions and the vulnerability's nature.
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| io.jenkins.plugins:cavisson-ns-nd-integration | maven | <= 4.8.0.129 | 4.8.0.130 |