CVE-2023-41939

HIGH

Jenkins SSH2 Easy Plugin <1.4 - Privilege Escalation

Title source: llm
STIX 2.1

Description

Jenkins SSH2 Easy Plugin 1.4 and earlier does not verify that permissions configured to be granted are enabled, potentially allowing users formerly granted (typically optional permissions, like Overall/Manage) to access functionality they're no longer entitled to.

Scores

CVSS v3 8.8
EPSS 0.0006
EPSS Percentile 18.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-281
Status published
Products (2)
jenkins/ssh2_easy < 1.4
org.jenkins-ci.plugins/ssh2easy 0 - 1.6Maven
Published Sep 06, 2023
Tracked Since Feb 18, 2026