Security Advisory

CVE-2023-50767

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2023-12-13 17:30:15
Last updated 2025-02-13 17:19:33
Assigner jenkins
CVSS score not scored
State PUBLISHED

Description

Missing permission checks in Jenkins Nexus Platform Plugin 3.18.0-03 and earlier allow attackers with Overall/Read permission to send an HTTP request to an attacker-specified URL and parse the response as XML.