-
CVSS Score
-Basic Information
CVE ID
-
GHSA ID
-
EPSS Score
-
CWE
-
Published
-
Updated
-
KEV Status
-
Technology
-
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| org.jenkins-ci.plugins:jclouds-jenkins | maven | <= 2.14 | 2.15 |
The vulnerability centers on form validation methods missing authorization checks. Both NVD and Jenkins security advisory explicitly name doTestConnection methods in BlobStoreProfile.DescriptorImpl and JCloudsCloud.DescriptorImpl as the vulnerable endpoints. These would appear in profilers when attackers trigger connection tests with malicious parameters. The methods' full names follow Java convention for Jenkins plugin descriptors.
Ongoing coverage of React2Shell