-
CVSS Score
-| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| org.jenkins-ci.main:jenkins-core | maven | < 2.3 | 2.3 |
The vulnerability centers on unauthorized access to plugin metadata via API endpoints. While exact patch details are unavailable, security advisories explicitly identify missing permissions checks in plugin-related XML/JSON API handlers. In Jenkins' architecture: