A missing permission check in Jenkins Nexus Task Runner Plugin 0.9.2 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-h83r-7f9f-mqjj | Jenkins Nexus Task Runner Plugin is missing a permission check |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Wed, 29 Oct 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-862 | |
| Metrics |
cvssV3_1
|
Wed, 29 Oct 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A missing permission check in Jenkins Nexus Task Runner Plugin 0.9.2 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials. | |
| References |
|
Status: PUBLISHED
Assigner: jenkins
Published:
Updated: 2025-10-29T13:59:29.245Z
Reserved: 2025-10-28T07:34:37.542Z
Link: CVE-2025-64142
Updated: 2025-10-29T13:59:22.194Z
Status : Received
Published: 2025-10-29T14:15:58.843
Modified: 2025-10-29T14:15:58.843
Link: CVE-2025-64142
No data.
OpenCVE Enrichment
No data.
Github GHSA