Required CVE Record Information
Description
Jenkins SSH2 Easy Plugin 1.4 and earlier does not verify that permissions configured to be granted are enabled, potentially allowing users formerly granted (typically optional permissions, like Overall/Manage) to access functionality they're no longer entitled to.
References 2 Total
Updated:
This container includes required additional information provided by the CVE Program for this vulnerability.
References 2 Total
- jenkins.io: Jenkins Security Advisory 2023-09-06 vendor-advisoryx_transferred
- http://www.openwall.com/lists/oss-security/2023/09/06/9 x_transferred