CVE-2025-47887

Source
https://nvd.nist.gov/vuln/detail/CVE-2025-47887
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-47887.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-47887
Aliases
Published
2025-05-14T21:15:59Z
Modified
2025-06-13T03:56:36.106529Z
Summary
[none]
Details

Missing permission checks in Jenkins Cadence vManager Plugin 4.0.1-286.v9e25a740ba_48 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified username and password.

References

Affected packages

Git / github.com/jenkinsci/vmanager-plugin

Affected ranges

Type
GIT
Repo
https://github.com/jenkinsci/vmanager-plugin
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected

Affected versions

4.*

4.0.0-268.v6360f91a_3d40
4.0.0-273.va_1c3509b_6603
4.0.0-282.v5096a_c2db_275
4.0.1-286.v9e25a_740b_a_48

vmanager-plugin-1.*

vmanager-plugin-1.1
vmanager-plugin-1.10
vmanager-plugin-1.2
vmanager-plugin-1.3
vmanager-plugin-1.4
vmanager-plugin-1.5
vmanager-plugin-1.6
vmanager-plugin-1.7
vmanager-plugin-1.8
vmanager-plugin-1.9

vmanager-plugin-2.*

vmanager-plugin-2.0
vmanager-plugin-2.1
vmanager-plugin-2.2
vmanager-plugin-2.3
vmanager-plugin-2.4
vmanager-plugin-2.4.1
vmanager-plugin-2.4.2
vmanager-plugin-2.4.3
vmanager-plugin-2.4.4
vmanager-plugin-2.4.5
vmanager-plugin-2.4.6
vmanager-plugin-2.4.7
vmanager-plugin-2.4.8
vmanager-plugin-2.4.9
vmanager-plugin-2.5.0
vmanager-plugin-2.5.1
vmanager-plugin-2.5.2
vmanager-plugin-2.5.3
vmanager-plugin-2.5.4
vmanager-plugin-2.5.5
vmanager-plugin-2.5.6
vmanager-plugin-2.5.7
vmanager-plugin-2.5.8
vmanager-plugin-2.5.9
vmanager-plugin-2.6.0
vmanager-plugin-2.7.0
vmanager-plugin-2.7.1

vmanager-plugin-3.*

vmanager-plugin-3.0.0
vmanager-plugin-3.0.1
vmanager-plugin-3.0.2
vmanager-plugin-3.0.3
vmanager-plugin-3.0.4
vmanager-plugin-3.0.5
vmanager-plugin-3.0.6
vmanager-plugin-3.0.7
vmanager-plugin-3.1
vmanager-plugin-3.1.1
vmanager-plugin-3.1.2
vmanager-plugin-3.1.3
vmanager-plugin-3.1.4
vmanager-plugin-3.1.5
vmanager-plugin-3.1.6
vmanager-plugin-3.1.7
vmanager-plugin-3.1.8
vmanager-plugin-3.2.0
vmanager-plugin-3.2.1
vmanager-plugin-3.2.1.1
vmanager-plugin-3.2.1.2
vmanager-plugin-3.2.1.3
vmanager-plugin-3.2.1.4
vmanager-plugin-3.2.1.5
vmanager-plugin-3.2.1.6
vmanager-plugin-3.2.1.7