Improper access control in Build Failure Analyzer - CVE-2023-43501
Published: September 21, 2023
Build Failure Analyzer
Jenkins
Description
The vulnerability allows a remote attacker to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to the affected plugin does not perform a permission check in a connection test HTTP endpoint. A remote user can connect to an attacker-specified hostname and port using attacker-specified username and password.