CVE-2023-50779: Medium severity jenkins vulnerability
Missing permission checks in Jenkins PaaSLane Estimate Plugin 1.0.4 and earlier allow attackers with Overall/Read permission to connect to an attacker-specified URL using an attacker-specified token.
Other sources
PaaSLane Estimate Plugin 1.0.4 and earlier does not perform permission checks in several HTTP endpoints. This allows attackers with Overall/Read permission to connect to an attacker-specified URL using an attacker-specified token.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-50779?
CVE-2023-50779 is considered to have a medium severity due to missing permission checks that could allow unauthorized access.
How do I fix CVE-2023-50779?
To fix CVE-2023-50779, update the Jenkins PaaSLane Estimate Plugin to version 1.0.5 or later.
Who is affected by CVE-2023-50779?
Users of Jenkins PaaSLane Estimate Plugin versions 1.0.4 and earlier are affected by CVE-2023-50779.
What is the nature of CVE-2023-50779 vulnerability?
CVE-2023-50779 allows attackers with Overall/Read permission to connect to arbitrary URLs using an attacker-specified token.
What kind of attacks are possible with CVE-2023-50779?
CVE-2023-50779 can be exploited to make unauthorized HTTP requests to external services using compromised credentials.