Description
Jenkins Assembla Auth Plugin 1.14 and earlier does not verify that the permissions it grants are enabled, resulting in users with EDIT permissions to be granted Overall/Manage and Overall/SystemRead permissions, even if those permissions are disabled and should not be granted.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-2575 | Jenkins Assembla Auth Plugin 1.14 and earlier does not verify that the permissions it grants are enabled, resulting in users with EDIT permissions to be granted Overall/Manage and Overall/SystemRead permissions, even if those permissions are disabled and should not be granted. |
Github GHSA |
GHSA-qf42-f5vf-6w99 | Disabled permissions granted by Jenkins Assembla Auth Plugin |
References
History
No history.
Status: PUBLISHED
Assigner: jenkins
Published:
Updated: 2024-09-26T20:40:47.076Z
Reserved: 2023-09-05T16:39:57.394Z
Link: CVE-2023-41945
No data.
Status : Modified
Published: 2023-09-06T13:15:11.770
Modified: 2024-11-21T08:21:58.460
Link: CVE-2023-41945
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA