Improper access control in Assembla Auth - CVE-2023-41945
Published: September 7, 2023
Assembla Auth
Jenkins
Description
The vulnerability allows a remote attacker to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to the affected plugin does not verify that the permissions it grants are enabled. A remote user can gain Overall/Manage and Overall/SystemRead permissions, even if those permissions are disabled and should not be granted.