Improper access control in NeuVector Vulnerability Scanner - CVE-2023-49674
Published: November 30, 2023
NeuVector Vulnerability Scanner
Jenkins
Description
The vulnerability allows a remote attacker to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to the affected plugin does not perform a permission check in a connection test HTTP endpoint. A remote user can connect to an attacker-specified hostname and port using attacker-specified username and password.