Vulnerability Details CVE-2023-41945
Jenkins Assembla Auth Plugin 1.14 and earlier does not verify that the permissions it grants are enabled, resulting in users with EDIT permissions to be granted Overall/Manage and Overall/SystemRead permissions, even if those permissions are disabled and should not be granted.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.0
EPSS Ranking 14.8%
CVSS Severity
CVSS v3 Score 8.8
Products affected by CVE-2023-41945
-
cpe:2.3:a:jenkins:assembla_auth:-
-
cpe:2.3:a:jenkins:assembla_auth:1.01
-
cpe:2.3:a:jenkins:assembla_auth:1.02
-
cpe:2.3:a:jenkins:assembla_auth:1.03
-
cpe:2.3:a:jenkins:assembla_auth:1.06
-
cpe:2.3:a:jenkins:assembla_auth:1.09
-
cpe:2.3:a:jenkins:assembla_auth:1.11
-
cpe:2.3:a:jenkins:assembla_auth:1.13
-
cpe:2.3:a:jenkins:assembla_auth:1.14