Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-fxp5-37mh-vff5

Опубликовано: 03 дек. 2025
Источник: github
Github: Прошло ревью
CVSS4: 5.3

Описание

BlazeMeter Jenkins Plugin is Missing Authorization for Available Resources

A fix was made in BlazeMeter Jenkins Plugin version 4.27 to allow users only with certain permissions to see the list of available resources like credential IDs, bzm workspaces and bzm project Ids. Prior to this fix, anyone could see this list as a dropdown on the Jenkins UI.

Пакеты

Наименование

com.blazemeter.plugins:BlazeMeterJenkinsPlugin

maven
Затронутые версииВерсия исправления

< 4.27

4.27

EPSS

Процентиль: 12%
0.00041
Низкий

5.3 Medium

CVSS4

Дефекты

CWE-862

Связанные уязвимости

nvd
2 месяца назад

A fix was made in BlazeMeter Jenkins Plugin version 4.27 to allow users only with certain permissions to see the list of available resources like credential IDs, bzm workspaces and bzm project Ids. Prior to this fix, anyone could see this list as a dropdown on the Jenkins UI.

EPSS

Процентиль: 12%
0.00041
Низкий

5.3 Medium

CVSS4

Дефекты

CWE-862