Fiche vulnérabilité
CVE-2023-41939 : faille élevée jenkins ssh2 easy (CVSS 8.8)
Description
Jenkins SSH2 Easy Plugin 1.4 and earlier does not verify that permissions configured to be granted are enabled, potentially allowing users formerly granted (typically optional permissions, like Overall/Manage) to access functionality they're no longer entitled to.
En bref
- Sévérité
- Élevée (CVSS 8.8)
- Vecteur CVSS
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Exploitation active
- Non signalée par la CISA
- Publication
- 6 sept. 2023
- Dernière mise à jour
- 17 juin 2026
Produits concernés
- jenkins ssh2 easy