CVE-2023-28668: Critical severity jenkins role-based authorization strategy vulnerability
Jenkins Role-based Authorization Strategy Plugin 587.v2872c41fae51 and earlier grants permissions even after they've been disabled.
Other sources
Permissions in Jenkins can be enabled and disabled. Some permissions are disabled by default, e.g., Overall/Manage or Item/Extended Read. Disabled permissions cannot be granted directly, only through greater permissions that imply them (e.g., Overall/Administer or Item/Configure).
Role-based Authorization Strategy Plugin 587.v2872c41fae51 and earlier grants permissions even after they’ve been disabled.
This allows attackers to have greater access than they’re entitled to after the following operations took place:
A permission is granted to attackers directly or through groups.
The permission is disabled, e.g., through the script console.
Role-based Authorization Strategy Plugin 587.588.v850a20a30162 does not grant disabled permissions.
Affected Software
Event History
Frequently Asked Questions
What is Jenkins Role-based Authorization Strategy Plugin CVE-2023-28668?
Jenkins Role-based Authorization Strategy Plugin CVE-2023-28668 is a vulnerability that allows permissions to be granted even after they've been disabled.
What is the severity of Jenkins Role-based Authorization Strategy Plugin CVE-2023-28668?
Jenkins Role-based Authorization Strategy Plugin CVE-2023-28668 has a severity rating of 9.8 (Critical).
How does Jenkins Role-based Authorization Strategy Plugin CVE-2023-28668 impact users?
Jenkins Role-based Authorization Strategy Plugin CVE-2023-28668 allows unauthorized users to still have permissions even if they've been disabled.
How can I fix Jenkins Role-based Authorization Strategy Plugin CVE-2023-28668?
To fix Jenkins Role-based Authorization Strategy Plugin CVE-2023-28668, update to version 587.v2872c41fa_e52 or later.
Where can I find more information about Jenkins Role-based Authorization Strategy Plugin CVE-2023-28668?
You can find more information about Jenkins Role-based Authorization Strategy Plugin CVE-2023-28668 on the Jenkins website: [link](https://www.jenkins.io/security/advisory/2023-03-21/#SECURITY-3053)