#VU103265 Improper access control in Folder-based Authorization Strategy - CVE-2025-24401
Published: January 23, 2025
Folder-based Authorization Strategy
Jenkins
Description
The vulnerability allows a remote attacker to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to the affected plugin does not verify that permissions configured to be granted are enabled. A remote user with formerly granted permissions can access functionality they are no longer entitled to.