Jenkins Build Failure Analyzer Plugin Vulnerability Exposes Sensitive Information
CVE-2023-43501
6.5MEDIUM
Key Information:
- Vendor
Jenkins
- Vendor
- CVE Published:
- 20 September 2023
What is CVE-2023-43501?
The Jenkins Build Failure Analyzer Plugin suffers from a critical issue due to a missing permission check, allowing users with Overall/Read permissions to establish connections to arbitrary hostnames and ports. This vulnerability enables attackers to exploit the plugin by using a username and password of their choosing, posing a significant risk of unauthorized access to sensitive data and systems. Users of versions 2.4.1 and earlier are urged to take immediate action to mitigate this vulnerability.
Affected Version(s)
Jenkins Build Failure Analyzer Plugin 0 <= 2.4.1