-
CVSS Score
-Basic Information
CVE ID
-
GHSA ID
-
EPSS Score
-
CWE
-
Published
-
Updated
-
KEV Status
-
Technology
-
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| io.jenkins.blueocean:blueocean | maven | <= 1.23.2 | 1.23.3 |
The vulnerability stemmed from missing Item/Create permission checks in HTTP endpoints handling connection tests for Bitbucket/GitHub servers. The commit 659a66a explicitly adds Jenkins.get().checkPermission(Item.CREATE) to these create methods, which aligns with the advisory's description of the fix. The added test cases (e.g., BitbucketServerEndpointSecuredTest) further confirm these methods were the attack vectors. No other functions in the provided code diffs show similar missing checks.
Ongoing coverage of React2Shell