CVE-2023-41939: Jenkins SSH2 Easy
High severity, CVSS 8.8. EPSS: 0.7% chance of exploitation in the next 30 days.
Jenkins SSH2 Easy Plugin 1.4 and earlier does not verify that permissions configured to be granted are enabled, potentially allowing users formerly granted (typically optional permissions, like Overall/Manage) to access functionality they're no longer entitled to.
Affected products
- Jenkins SSH2 Easy: up to and including 1.4
Published 2023-09-06. Last modified 2026-06-17.