A missing permission check in Jenkins Build Failure Analyzer Plugin 2.4.1 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified hostname and port using attacker-specified username and password.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: jenkins

Published: 2023-09-20T16:06:12.873Z

Updated: 2023-10-24T12:52:08.360Z

Reserved: 2023-09-19T09:22:58.131Z


Link: CVE-2023-43501

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2023-09-20T17:15:12.090

Modified: 2023-09-22T19:04:23.370


Link: CVE-2023-43501

JSON object: View

cve-icon Redhat Information

No data.

CWE