Permission Check Flaw in Jenkins Report Portal Plugin by Jenkins
CVE-2023-30526
6.5MEDIUM
What is CVE-2023-30526?
A vulnerability exists in the Jenkins Report Portal Plugin prior to version 0.5, where a missing permission check enables attackers with Overall/Read permissions to connect to user-specified URLs using bearer token authentication. This flaw can potentially be exploited to access unauthorized information or perform actions that should not be permitted, posing a risk to the integrity and confidentiality of user data.
Affected Version(s)
Jenkins Report Portal Plugin 0 <= 0.5