First published: Wed Sep 06 2023(Updated: )
Jenkins SSH2 Easy Plugin 1.4 and earlier does not verify that permissions configured to be granted are enabled, potentially allowing users formerly granted (typically optional permissions, like Overall/Manage) to access functionality they're no longer entitled to.
Credit: jenkinsci-cert@googlegroups.com jenkinsci-cert@googlegroups.com jenkinsci-cert@googlegroups.com
Affected Software | Affected Version | How to fix |
---|---|---|
Jenkins Ssh2 Easy | <=1.4 | |
maven/org.jenkins-ci.plugins:ssh2easy | <1.6 | 1.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2023-41939.
The severity of CVE-2023-41939 is high with a CVSS score of 8.8.
The affected software for CVE-2023-41939 is Jenkins SSH2 Easy Plugin version 1.4 and earlier.
CVE-2023-41939 refers to a vulnerability in Jenkins SSH2 Easy Plugin where permissions configured to be granted are not verified, potentially allowing unauthorized access to functionality.
Yes, you can find references for CVE-2023-41939 at the following links: [1] http://www.openwall.com/lists/oss-security/2023/09/06/9 [2] https://www.jenkins.io/security/advisory/2023-09-06/#SECURITY-3064