Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-0148 | Jenkins Folder-based Authorization Strategy Plugin 217.vd5b_18537403e and earlier does not verify that permissions configured to be granted are enabled, potentially allowing users formerly granted (typically optional permissions, like Overall/Manage) to access functionality they're no longer entitled to. |
Github GHSA |
GHSA-969g-rq57-c79h | Disabled permissions can be granted by Folder-based in Jenkins Authorization Strategy Plugin |
Fri, 03 Oct 2025 00:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Jenkins
Jenkins folder-based Authorization Strategy |
|
| CPEs | cpe:2.3:a:jenkins:folder-based_authorization_strategy:*:*:*:*:*:jenkins:*:* | |
| Vendors & Products |
Jenkins
Jenkins folder-based Authorization Strategy |
Thu, 23 Jan 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-863 | |
| Metrics |
cvssV3_1
|
Wed, 22 Jan 2025 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Jenkins Folder-based Authorization Strategy Plugin 217.vd5b_18537403e and earlier does not verify that permissions configured to be granted are enabled, potentially allowing users formerly granted (typically optional permissions, like Overall/Manage) to access functionality they're no longer entitled to. | |
| References |
|
Status: PUBLISHED
Assigner: jenkins
Published:
Updated: 2025-01-23T16:07:38.504Z
Reserved: 2025-01-21T12:41:49.875Z
Link: CVE-2025-24401
Updated: 2025-01-23T16:06:49.336Z
Status : Analyzed
Published: 2025-01-22T17:15:14.027
Modified: 2025-10-03T00:15:30.693
Link: CVE-2025-24401
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA