Jenkins Failed Job Deactivator Plugin 1.2.1 and earlier does not perform permission checks in several views and HTTP endpoints, allowing attackers with Overall/Read permission to disable jobs.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| de.einsundeins.jenkins.plugins.failedjobdeactivator:failedJobDeactivator(Maven) | 0 | N/A | N/A |
CVSS Metrics