CVE-2023-41945: High severity jenkins assembla auth vulnerability
Jenkins Assembla Auth Plugin 1.14 and earlier does not verify that the permissions it grants are enabled, resulting in users with EDIT permissions to be granted Overall/Manage and Overall/SystemRead permissions, even if those permissions are disabled and should not be granted.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for Jenkins Assembla Auth Plugin?
The vulnerability ID for Jenkins Assembla Auth Plugin is CVE-2023-41945.
What is the severity of CVE-2023-41945?
The severity of CVE-2023-41945 is high with a CVSS score of 8.8.
What is the affected software for CVE-2023-41945?
The affected software for CVE-2023-41945 is Jenkins Assembla Auth Plugin version 1.14 and earlier.
What is the impact of CVE-2023-41945?
CVE-2023-41945 allows users with EDIT permissions to be granted Overall/Manage and Overall/SystemRead permissions, even if they are disabled and should not be granted.
Are there any references for CVE-2023-41945?
Yes, you can find references for CVE-2023-41945 at the following links: [1](http://www.openwall.com/lists/oss-security/2023/09/06/9) and [2](https://www.jenkins.io/security/advisory/2023-09-06/#SECURITY-3065).