A missing permission check in Jenkins Digital.ai App Management Publisher Plugin 2.6 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL, capturing credentials stored in Jenkins.
CVE ID: CVE-2023-35149
Vendor: Jenkins Project
Product: Jenkins Digital.ai App Management Publisher Plugin
EPSS Score: 0.08% (probability of being exploited)
EPSS Percentile: 37.61% (scored less or equal to compared to others)
EPSS Date: 2025-02-04 (when was this score calculated)