CVEs (4)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Jenkins 1Role Based Authorization Strategy Jun 17, 2026 Apr 2, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2 Jenkins Role-based Authorization Strategy Plugin 587.v2872c41fa_e51 and earlier grants permissions even after they've been disabled. |
1Jenkins 1Role Based Authorization Strategy Jun 17, 2026 Mar 18, 2021 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 An incorrect permission check in Jenkins Role-based Authorization Strategy Plugin 3.1 and earlier allows attackers with Item/Read permission on nested items to access them, even if they lack Item/Read permission for pare...Show more |
1Jenkins 1Role Based Authorization Strategy Jun 17, 2026 Oct 8, 2020 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Jenkins Role-based Authorization Strategy Plugin 3.0 and earlier does not properly invalidate a permission cache when the configuration is changed, resulting in permissions being granted based on an outdated configuratio...Show more |
1Jenkins 1Role Based Authorization Strategy May 13, 2026 Oct 5, 2017 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Role-based Authorization Strategy Plugin was not requiring requests to its API be sent via POST, thereby opening itself to Cross-Site Request Forgery attacks. This allowed attackers to add administrator role to any user,...Show more |