Missing Permission Checks in Jenkins Cadence vManager Plugin
CVE-2025-47887
4.3MEDIUM
Key Information:
- Vendor
Jenkins
- Vendor
- CVE Published:
- 14 May 2025
What is CVE-2025-47887?
The Jenkins Cadence vManager Plugin contains a significant vulnerability due to missing permission checks. Attackers with Overall/Read permission can exploit this flaw to connect to arbitrary URLs using credentials they specify. This allows unauthorized access and could compromise sensitive data, emphasizing the need for prompt updates to safeguard against potential attacks.
Affected Version(s)
Jenkins Cadence vManager Plugin 0 <= 4.0.1-286.v9e25a_740b_a_48