Advisories for Maven/Org.jenkins-Ci.plugins/Dockerhub-Notification package

2022

Lack of authentication mechanism for webhook in CloudBees Docker Hub/Registry Notification Plugin

CloudBees Docker Hub/Registry Notification Plugin provides several webhook endpoints that can be used to trigger builds when Docker images used by a job have been rebuilt. In CloudBees Docker Hub/Registry Notification Plugin 2.6.2 and earlier, these endpoints can be accessed without authentication. This allows unauthenticated attackers to trigger builds of jobs corresponding to the attacker-specified repository. CloudBees Docker Hub/Registry Notification Plugin 2.6.2.1 requires a token as a part of webhook …