Missing permission checks in Jenkins Cadence vManager Plugin 4.0.1-286.v9e25a_740b_a_48 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified username and password.
Metrics
Affected Vendors & Products
References
History
Thu, 12 Jun 2025 14:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Jenkins
Jenkins cadence Vmanager |
|
CPEs | cpe:2.3:a:jenkins:cadence_vmanager:*:*:*:*:*:jenkins:*:* | |
Vendors & Products |
Jenkins
Jenkins cadence Vmanager |
Thu, 15 May 2025 14:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-862 | |
Metrics |
cvssV3_1
|
Wed, 14 May 2025 20:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Missing permission checks in Jenkins Cadence vManager Plugin 4.0.1-286.v9e25a_740b_a_48 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified username and password. | |
References |
|

Status: PUBLISHED
Assigner: jenkins
Published: 2025-05-14T20:35:56.876Z
Updated: 2025-05-15T13:26:54.921Z
Reserved: 2025-05-13T12:21:13.541Z
Link: CVE-2025-47887

Updated: 2025-05-15T13:26:38.315Z

Status : Analyzed
Published: 2025-05-14T21:15:59.657
Modified: 2025-06-12T13:33:00.233
Link: CVE-2025-47887

No data.