CVE-2025-47887: Medium severity cadence vmanager plugin vulnerability
Missing permission checks in Jenkins Cadence vManager Plugin 4.0.1-286.v9e25a740ba48 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified username and password.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-47887?
CVE-2025-47887 has a high severity rating due to the potential for unauthorized access to sensitive information.
How do I fix CVE-2025-47887?
To fix CVE-2025-47887, upgrade to the latest version of the Jenkins Cadence vManager Plugin that addresses the missing permission checks.
Who is affected by CVE-2025-47887?
Users of Jenkins Cadence vManager Plugin version 4.0.1-286.v9e25a_740b_a_48 and earlier are affected by CVE-2025-47887.
What vulnerabilities does CVE-2025-47887 expose?
CVE-2025-47887 exposes the application to risks from attackers who can leverage Overall/Read permissions to connect to arbitrary URLs.
Are there any known exploits for CVE-2025-47887?
As of now, there are no widely verified exploits publicly reported for CVE-2025-47887, but the vulnerability itself poses a significant risk.