Jenkins SSH2 Easy Plugin 1.4 and earlier does not verify that permissions configured to be granted are enabled, potentially allowing users formerly granted (typically optional permissions, like Overall/Manage) to access functionality they're no longer entitled to.
{ "github_reviewed_at": "2024-01-30T23:07:24Z", "cwe_ids": [ "CWE-281" ], "nvd_published_at": "2023-09-06T13:15:10Z", "severity": "HIGH", "github_reviewed": true }