ZeroHour

CVE-2023-41939

CVSS 3.1
8.8 high
EPSS
<1%p50
Published
()
Modified
Description

Jenkins SSH2 Easy Plugin 1.4 and earlier does not verify that permissions configured to be granted are enabled, potentially allowing users formerly granted (typically optional permissions, like Overall/Manage) to access functionality they're no longer entitled to.

Vendors
jenkins
Products
ssh2 easy
Weakness
CWE-281
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.