Loading HuntDB...

GHSA-cj2x-r74q-vcx9

GitHub Security Advisory

Missing authorization in Jenkins Plug-in for ServiceNow

✓ GitHub Reviewed HIGH Has CVE

Advisory Details

A missing authorization vulnerability exists in versions of the Jenkins Plug-in for ServiceNow DevOps prior to 1.38.1 that, if exploited successfully, could cause the unwanted exposure of sensitive information. To address this issue, apply the 1.38.1 version of the Jenkins plug-in for ServiceNow DevOps on your Jenkins server. No changes are required on your instances of the Now Platform.

Affected Packages

Maven io.jenkins.plugins:servicenow-devops
Affected versions: 0 (fixed in 1.38.1)

Related CVEs

Key Information

GHSA ID
GHSA-cj2x-r74q-vcx9
Published
July 26, 2023 9:30 PM
Last Modified
August 3, 2023 7:36 PM
CVSS Score
7.5 /10
Primary Ecosystem
Maven
Primary Package
io.jenkins.plugins:servicenow-devops
GitHub Reviewed
✓ Yes

Dataset

Last updated: July 13, 2025 6:28 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.