cbcvebase.
CVE-2023-28675
published 2023-04-02

CVE-2023-28675: A missing permission check in Jenkins OctoPerf Load Testing Plugin Plugin 4.5.2 and earlier allows attackers to connect to a previously configured Octoperf…

PriorityP422medium4.3CVSS 3.1
AVNACLPRLUINSUCNILAN
EPSS
0.43%
34.4th percentile
A missing permission check in Jenkins OctoPerf Load Testing Plugin Plugin 4.5.2 and earlier allows attackers to connect to a previously configured Octoperf server using attacker-specified credentials.

Affected

15 ranges
VendorProductVersion rangeFixed in
jenkinsabsint_a_plugin
jenkinsconvert_to_pipeline_plugin
jenkinscppcheck_plugin
jenkinscrap4j_plugin
jenkinsids_in_octoperf_load_testing_plugin
jenkinsjacoco_plugin
jenkinsmashup_portlets_plugin
jenkinsoctoperf_load_testing<= 4.5.2
jenkinsoctoperf_load_testing_plugin
jenkinsperformance_publisher_plugin
jenkinsphabricator_differential_plugin
jenkinspipeline_aggregator_view_plugin
jenkinsrole-based_authorization_strategy_plugin
jenkinsvisual_studio_code_metrics_plugin
jenkins_projectjenkins_octoperf_load_testing_plugin_plugin<= 4.5.2
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.