Description
Missing permission checks in Jenkins PaaSLane Estimate Plugin 1.0.4 and earlier allow attackers with Overall/Read permission to connect to an attacker-specified URL using an attacker-specified token.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-jqr2-7f24-xrgc | Missing permission check in Jenkins PaaSLane Estimate Plugin |
References
History
No history.
Status: PUBLISHED
Assigner: jenkins
Published:
Updated: 2025-02-13T17:19:40.136Z
Reserved: 2023-12-13T13:06:36.478Z
Link: CVE-2023-50779
No data.
Status : Modified
Published: 2023-12-13T18:15:44.467
Modified: 2024-11-21T08:37:17.907
Link: CVE-2023-50779
No data.
OpenCVE Enrichment
No data.
Weaknesses
Github GHSA