{"id":"GHSA-436g-2f92-cvhh","summary":"Jenkins Role-based Authorization Strategy Plugin grants permissions even after they’ve been disabled","details":"Permissions in Jenkins can be enabled and disabled. Some permissions are disabled by default, e.g., Overall/Manage or Item/Extended Read. Disabled permissions cannot be granted directly, only through greater permissions that imply them (e.g., Overall/Administer or Item/Configure).\n\nRole-based Authorization Strategy Plugin 587.v2872c41fa_e51 and earlier grants permissions even after they’ve been disabled.\n\nThis allows attackers to have greater access than they’re entitled to after the following operations took place:\n\nA permission is granted to attackers directly or through groups.\n\nThe permission is disabled, e.g., through the script console.\n\nRole-based Authorization Strategy Plugin 587.588.v850a_20a_30162 does not grant disabled permissions.","aliases":["CVE-2023-28668"],"modified":"2025-02-25T22:08:11.499262Z","published":"2023-04-02T21:30:17Z","database_specific":{"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2023-04-03T22:55:17Z","nvd_published_at":"2023-04-02T21:15:00Z","cwe_ids":["CWE-281"]},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-28668"},{"type":"WEB","url":"https://github.com/jenkinsci/role-strategy-plugin/commit/850a20a3016276d0c0ba4898a876c113a9191da4"},{"type":"WEB","url":"https://www.jenkins.io/security/advisory/2023-03-21/#SECURITY-3053"}],"affected":[{"package":{"name":"org.jenkins-ci.plugins:role-strategy","ecosystem":"Maven","purl":"pkg:maven/org.jenkins-ci.plugins/role-strategy"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"587.588.v850a_20a_30162"}]}],"versions":["1.1.2","1.1.3","2.1.0","2.10","2.11","2.12","2.13","2.14","2.15","2.16","2.2.0","2.3.0","2.3.1","2.3.2","2.4.0","2.5.0","2.5.1","2.6.0","2.6.1","2.7.0","2.8.0","2.8.1","2.8.2","2.9.0","3.0","3.1","3.1.1","3.2.0","483.v17281966f5c3","484.v8a_a_e4b_d785fd","488.v0634ce149b_8c","501.v88fe53d65c80","506.v13f908ee1fc9","508.v2a_f05b_05e9d8","510.v909834359ec2","521.vcf7a_3a_8dde42","526.v859673312a_14","530.ved5445d4875a_","546.ve16648865996","548.vb_60076577ec7","552.v14cb_85499b_89","555.v8d194cc85b_30","561.v9846c7351a_41","562.v44e9a_e828d0e","569.v7476f8e4fe29","575.v4d286a_03e6d7","584.vf8e515397ecd","587.v2872c41fa_e51"],"database_specific":{"last_known_affected_version_range":"\u003c 587.588.v850a","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/04/GHSA-436g-2f92-cvhh/GHSA-436g-2f92-cvhh.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:L/A:N"}]}