8.8
CVSSv3

CVE-2023-41945

Published: 06/09/2023 Updated: 11/09/2023
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 0

Vulnerability Summary

Jenkins Assembla Auth Plugin 1.14 and previous versions does not verify that the permissions it grants are enabled, resulting in users with EDIT permissions to be granted Overall/Manage and Overall/SystemRead permissions, even if those permissions are disabled and should not be granted.

Vulnerable Product Search on Vulmon Subscribe to Product

jenkins assembla auth