cbcvebase.
CVE-2025-47887
published 2025-05-14

CVE-2025-47887: Missing permission checks in Jenkins Cadence vManager Plugin 4.0.1-286.v9e25a_740b_a_48 and earlier allows attackers with Overall/Read permission to connect to…

medium4.3CVSS 3.1
AVNACLPRLUINSUCNILAN
Missing permission checks in Jenkins Cadence vManager Plugin 4.0.1-286.v9e25a_740b_a_48 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified username and password.

Affected

10 ranges
VendorProductVersion rangeFixed in
jenkinscadence_vmanager<= 4.0.1-286.v9e25a_740b_a_48
jenkinscadence_vmanager_plugin
jenkinsdingtalk_plugin
jenkinsenvironment_injector_plugin
jenkinshealth_advisor_by_cloudbees_plugin
jenkinsmatrix_authorization_strategy_plugin
jenkinsopenid_connect_provider_plugin
jenkinsrole-based_authorization_strategy_plugin
jenkinswso2_oauth_plugin
jenkins_projectjenkins_cadence_vmanager_plugin<= 4.0.1-286.v9e25a_740b_a_48