-
CVSS Score
-Basic Information
CVE ID
-
GHSA ID
-
EPSS Score
-
CWE
-
Published
-
Updated
-
KEV Status
-
Technology
-
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| com.convertigo.jenkins.plugins:convertigo-mobile-platform | maven | <= 1.1 |
The advisory specifies a missing permission check in form validation methods. Jenkins plugin patterns indicate URL validation methods (typically doCheck* methods in DescriptorImpl classes) are used for input validation. The vulnerability allows URL connection abuse, which aligns with form validation handlers that check URL reachability without proper authorization checks. The descriptor class for ConvertigoBuilder is the most probable location given the plugin's functionality.
Ongoing coverage of React2Shell