cbcvebase.
CVE-2023-30526
published 2023-04-12

CVE-2023-30526: A missing permission check in Jenkins Report Portal Plugin 0.5 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified…

PriorityP337medium6.5CVSS 3.1
AVNACLPRLUINSUCNIHAN
EPSS
0.54%
41.8th percentile
A missing permission check in Jenkins Report Portal Plugin 0.5 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified bearer token authentication.

Affected

16 ranges
VendorProductVersion rangeFixed in
jenkinsassembla_merge_request_builder_plugin
jenkinsazure_key_vault_plugin
jenkinsconsul_kv_builder_plugin
jenkinsdelinea_secret_server_platform_plugin
jenkinsfogbugz_plugin
jenkinsimage_tag_parameter_plugin
jenkinskubernetes_plugin
jenkinslack_of_authentication_mechanism_in_fogbugz_plugin
jenkinslack_of_authentication_mechanism_in_turboscript_plugin
jenkinslucene-search_plugin
jenkinsquay.io_trigger_plugin
jenkinsreport_portal<= 0.5
jenkinsreport_portal_plugin
jenkinsthycotic_devops_secrets_vault_plugin
jenkinsturboscript_plugin
jenkins_projectjenkins_report_portal_plugin<= 0.5
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.