GHSA-4gh2-m88h-8cj8
GitHub Security Advisory
Disabled permissions can be granted by Jenkins SSH2 Easy Plugin
✓ GitHub Reviewed
HIGH
Has CVE
Advisory Details
Jenkins SSH2 Easy Plugin 1.4 and earlier does not verify that permissions configured to be granted are enabled, potentially allowing users formerly granted (typically optional permissions, like Overall/Manage) to access functionality they're no longer entitled to.
Affected Packages
Maven
org.jenkins-ci.plugins:ssh2easy
Affected versions:
0
(fixed in 1.6)
Related CVEs
Key Information
7.5
/10
Dataset
Last updated: August 24, 2025 6:28 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.