cbcvebase.
CVE-2023-28668
published 2023-04-02

CVE-2023-28668: Jenkins Role-based Authorization Strategy Plugin 587.v2872c41fa_e51 and earlier grants permissions even after they've been disabled.

critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
Jenkins Role-based Authorization Strategy Plugin 587.v2872c41fa_e51 and earlier grants permissions even after they've been disabled.

Affected

15 ranges
VendorProductVersion rangeFixed in
jenkinsabsint_a_plugin
jenkinsconvert_to_pipeline_plugin
jenkinscppcheck_plugin
jenkinscrap4j_plugin
jenkinsids_in_octoperf_load_testing_plugin
jenkinsjacoco_plugin
jenkinsmashup_portlets_plugin
jenkinsoctoperf_load_testing_plugin
jenkinsperformance_publisher_plugin
jenkinsphabricator_differential_plugin
jenkinspipeline_aggregator_view_plugin
jenkinsrole-based_authorization_strategy<= 587.v2872c41fa_e51
jenkinsrole-based_authorization_strategy_plugin
jenkinsvisual_studio_code_metrics_plugin
jenkins_projectjenkins_role-based_authorization_strategy_plugin<= 587.v2872c41fa_e51