{"id":"GHSA-w4v5-54p8-m4j5","summary":"Missing permission checks in Jenkins GitHub Pull Request Builder Plugin","details":"A missing permission check in Jenkins GitHub Pull Request Builder Plugin 1.42.2 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.","aliases":["CVE-2023-24435"],"modified":"2026-08-24T00:35:20.833752348Z","published":"2023-01-26T21:30:18Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2023-01-27T01:20:04Z","nvd_published_at":"2023-01-26T21:18:00Z","cwe_ids":["CWE-862"],"severity":"MODERATE"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-24435"},{"type":"PACKAGE","url":"https://github.com/jenkinsci/ghprb-plugin"},{"type":"WEB","url":"https://www.jenkins.io/security/advisory/2023-01-24/#SECURITY-2789%20(2)"}],"affected":[{"package":{"name":"org.jenkins-ci.plugins:ghprb","ecosystem":"Maven","purl":"pkg:maven/org.jenkins-ci.plugins/ghprb"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"1.42.2"}]}],"versions":["1.0","1.1","1.1.1","1.11.2","1.12","1.13","1.13-1","1.14","1.14-1","1.14-2","1.14-3","1.14-4","1.14-5","1.14-6","1.14-7","1.15-0","1.15-1","1.16-0","1.16-1","1.16-2","1.16-3","1.16-4","1.16-5","1.16-6","1.16-7","1.16-8","1.17","1.18","1.19","1.2","1.20","1.20.1","1.21","1.21.1","1.22","1.22.1","1.22.2","1.22.3","1.22.4","1.23","1.23.1","1.23.2","1.23.3","1.24","1.24.1","1.24.2","1.24.3","1.24.4","1.24.5","1.24.6","1.24.7","1.24.8","1.25","1.26","1.26.1","1.26.2","1.27","1.28","1.28.1","1.28.2","1.28.3","1.28.4","1.28.6","1.29","1.29.1","1.29.2","1.29.3","1.29.4","1.29.5","1.29.6","1.29.7","1.29.8","1.3","1.3.1","1.3.2","1.30","1.30.1","1.30.2","1.30.3","1.30.4","1.30.5","1.30.6","1.31.1","1.31.2","1.31.3","1.31.4","1.32.1","1.32.2","1.32.3","1.32.4","1.32.5","1.32.6","1.32.7","1.32.8","1.33.0","1.33.1","1.33.2","1.33.3","1.33.4","1.34.0","1.35.0","1.36.0","1.36.1","1.36.2","1.37.0","1.38.0","1.39.0","1.4","1.40.0","1.41.0","1.42.0","1.42.1","1.42.2","1.5","1.5.1","1.7","1.8","1.9"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/01/GHSA-w4v5-54p8-m4j5/GHSA-w4v5-54p8-m4j5.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"}]}