Loading HuntDB...

GHSA-4gh2-m88h-8cj8

GitHub Security Advisory

Disabled permissions can be granted by Jenkins SSH2 Easy Plugin

✓ GitHub Reviewed HIGH Has CVE

Advisory Details

Jenkins SSH2 Easy Plugin 1.4 and earlier does not verify that permissions configured to be granted are enabled, potentially allowing users formerly granted (typically optional permissions, like Overall/Manage) to access functionality they're no longer entitled to.

Affected Packages

Maven org.jenkins-ci.plugins:ssh2easy
Affected versions: 0 (fixed in 1.6)

Related CVEs

Key Information

GHSA ID
GHSA-4gh2-m88h-8cj8
Published
September 6, 2023 3:30 PM
Last Modified
January 30, 2024 11:07 PM
CVSS Score
7.5 /10
Primary Ecosystem
Maven
Primary Package
org.jenkins-ci.plugins:ssh2easy
GitHub Reviewed
✓ Yes

Dataset

Last updated: August 24, 2025 6:28 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.