Improper Authorization in Jenkins Black Duck Hub Plugin
CVE-2018-1000197
8.1HIGH
What is CVE-2018-1000197?
An improper authorization vulnerability in versions of the Jenkins Black Duck Hub Plugin prior to 3.0.3 allows users with Overall/Read permissions to manipulate the plugin's configuration settings. This flaw can lead to unauthorized access to sensitive configuration data, potentially compromising the security posture of integrated applications.