CVE Database
/

CVE-2025-47887

Back to search

CVE-2025-47887

Published: May 14, 2025

Modified: May 15, 2025

PUBLISHED

Description

Missing permission checks in Jenkins Cadence vManager Plugin 4.0.1-286.v9e25a_740b_a_48 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified username and password.

VendorProductVersions

Jenkins Project

Jenkins Cadence vManager Plugin

affected
0 - <= 4.0.1-286.v9e25a_740b_a_48

References

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now