-
CVSS Score
-Basic Information
CVE ID
-
GHSA ID
-
EPSS Score
-
CWE
-
Published
-
Updated
-
KEV Status
-
Technology
-
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| org.jenkins-ci.plugins:cons3rt | maven | <= 1.0.0 |
The vulnerability explicitly states missing permission checks in HTTP endpoints. Jenkins plugins typically implement endpoints via do* methods in Java classes. While exact method names aren't provided in advisories, the pattern matches CWE-862 where endpoints handling credential operations would normally require SystemCredentialsProvider.VIEW permission but lack these checks. The high confidence comes from multiple independent sources (NVD, GHSA, Jenkins advisory) confirming the missing authorization mechanism in endpoint handlers.
Ongoing coverage of React2Shell