-
CVSS Score
-Basic Information
CVE ID
-
GHSA ID
-
EPSS Score
-
CWE
-
Published
-
Updated
-
KEV Status
-
Technology
-
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| org.jenkins-ci.plugins:openshift-deployer | maven | <= 1.2.0 |
The vulnerability description explicitly identifies DeployApplication.DeployApplicationDescriptor#doCheckLogin as the method with a missing permission check. Jenkins plugin security patterns indicate form validation methods (doCheck* prefixes) require explicit permission checks, which are missing here. The CWE-862 classification and advisory details confirm this is an authorization bypass at the function level.
Ongoing coverage of React2Shell