CVE-2023-41943

CVSS v3.1 6.5 (Medium)
65% Progress
EPSS 0.07 % (32th)
0.07% Progress
Affected Products 1
Advisories 2

Jenkins AWS CodeCommit Trigger Plugin 3.0.12 and earlier does not perform a permission check in an HTTP endpoint, allowing attackers with Overall/Read permission to clear the SQS queue.

Weaknesses
CWE-862
Missing Authorization
CVE Status
PUBLISHED
CNA
Jenkins Project
Published Date
2023-09-06 13:15:11
(12 months ago)
Updated Date
2023-09-11 18:40:55
(12 months ago)

Affected Products

Loading...
Loading...
Loading...

Configuration #1

    CPE23 From Up To
  Jenkins Aws Codecommit Trigger for Jenkins 3.0.12 and prior versions cpe:2.3:a:jenkins:aws_codecommit_trigger::*:*:*:*:jenkins <= 3.0.12
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...