CVE-2023-43501
20.09.2023, 17:15
A missing permission check in Jenkins Build Failure Analyzer Plugin 2.4.1 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified hostname and port using attacker-specified username and password.Enginsight
Vendor | Product | Version |
---|---|---|
jenkins | build_failure_analyzer | 𝑥 < 2.4.2 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration