Description
A missing permission check in Jenkins Build Failure Analyzer Plugin 1.24.1 and earlier allows attackers with Overall/Read permission to have Jenkins evaluate a computationally expensive regular expression.
Affected products
- Jenkins Project / Jenkins Build Failure Analyzer Pluginunspecified – 1.24.1