Jenkins Cadence vManager Plugin is Missing Permission Checks
Moderate severity
GitHub Reviewed
Published
May 14, 2025
to the GitHub Advisory Database
•
Updated May 16, 2025
Package
Affected versions
< 4.0.1-288.v8804beaacb7f
Patched versions
4.0.1-288.v8804b_ea_a_cb_7f
Description
Published by the National Vulnerability Database
May 14, 2025
Published to the GitHub Advisory Database
May 14, 2025
Reviewed
May 16, 2025
Last updated
May 16, 2025
Missing permission checks in Jenkins Cadence vManager Plugin 4.0.1-286.v9e25a_740b_a_48 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified username and password.
References