CVE-2023-49674
29.11.2023, 14:15
A missing permission check in Jenkins NeuVector Vulnerability Scanner Plugin 1.22 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified hostname and port using attacker-specified username and password.Enginsight
Vendor | Product | Version |
---|---|---|
jenkins | neuvector_vulnerability_scanner | 𝑥 ≤ 1.22 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration