Show filters
4 Total Results
Displaying 1-4 of 4
Sort by:
Attacker Value
Unknown
CVE-2023-28668
Disclosure Date: April 02, 2023 (last updated February 24, 2025)
Jenkins Role-based Authorization Strategy Plugin 587.v2872c41fa_e51 and earlier grants permissions even after they've been disabled.
0
Attacker Value
Unknown
CVE-2021-21624
Disclosure Date: March 18, 2021 (last updated February 22, 2025)
An incorrect permission check in Jenkins Role-based Authorization Strategy Plugin 3.1 and earlier allows attackers with Item/Read permission on nested items to access them, even if they lack Item/Read permission for parent folders.
0
Attacker Value
Unknown
CVE-2020-2286
Disclosure Date: October 08, 2020 (last updated October 26, 2023)
Jenkins Role-based Authorization Strategy Plugin 3.0 and earlier does not properly invalidate a permission cache when the configuration is changed, resulting in permissions being granted based on an outdated configuration.
0
Attacker Value
Unknown
CVE-2017-1000090
Disclosure Date: October 05, 2017 (last updated November 26, 2024)
Role-based Authorization Strategy Plugin was not requiring requests to its API be sent via POST, thereby opening itself to Cross-Site Request Forgery attacks. This allowed attackers to add administrator role to any user, or to remove the authorization configuration, preventing legitimate access to Jenkins.
0