Back

HIGH

Missing Authorization in Jenkins plug-in for ServiceNow DevOps

Published Jul 26, 2023

Description

A missing authorization vulnerability exists in versions of the Jenkins Plug-in for ServiceNow DevOps prior to 1.38.1 that, if exploited successfully, could cause the unwanted exposure of sensitive information. To address this issue, apply the 1.38.1 version of the Jenkins plug-in for ServiceNow DevOps on your Jenkins server. No changes are required on your instances of the Now Platform.

Affected products

Remediation

No remediation recorded yet.

References (7)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner SN
Published Jul 26, 2023
Updated Oct 15, 2024
Reserved Jun 28, 2023

CISA Vulnrichment

Updated Oct 15, 2024

NVD

Status Modified
Modified Jun 17, 2026

Red Hat

No data

ENISA EUVD

Assigner SN
Published Jul 26, 2023
Updated Oct 15, 2024