-
CVSS Score
-| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| org.jenkins-ci.plugins:jenkins-reviewbot | maven | <= 2.4.6 |
The vulnerability description explicitly identifies ReviewboardDescriptor#doTestConnection as the vulnerable method. Jenkins form validation methods (do* methods) are common attack surfaces for missing permission checks. The CWE-862 classification confirms this is an authorization bypass issue. Multiple sources (NVD, GHSA, Jenkins advisory) consistently describe the flaw as a missing permission check in this specific method. The pattern matches known Jenkins plugin vulnerabilities where form validation endpoints lack @RequirePermissions annotations or equivalent authorization checks.