CVE Database
/

CVE-2023-41945

Back to search

CVE-2023-41945

Published: Sep 6, 2023

Modified: Sep 26, 2024

PUBLISHED

Description

Jenkins Assembla Auth Plugin 1.14 and earlier does not verify that the permissions it grants are enabled, resulting in users with EDIT permissions to be granted Overall/Manage and Overall/SystemRead permissions, even if those permissions are disabled and should not be granted.

VendorProductVersions

Jenkins Project

Jenkins Assembla Auth Plugin

affected
0 - <= 1.14

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now