-
CVSS Score
-Basic Information
CVE ID
-
GHSA ID
-
EPSS Score
-
CWE
-
Published
-
Updated
-
KEV Status
-
Technology
-
The commit diff shows the permission check was upgraded from MANAGE to ADMINISTER in doTestConnection. Jenkins.MANAGE is a weaker permission (typically for plugin configuration) while ADMINISTER is required for sensitive operations. The vulnerability allowed unauthorized users to trigger network calls with stored credentials, consistent with CWE-862 (Missing Authorization). The function's purpose (testing external connections) makes it a clear vector for credential leakage via SSRF when improperly secured.
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| io.jenkins.plugins:servicenow-devops | maven | < 1.38.1 | 1.38.1 |
KEV Misses 88% of Exploited CVEs- Get the report