Junglewise Threat Intelligence

CVE-2023-28675: Jenkins OctoPerf Load Testing Plugin missing permission check allows for unauthorized server connections

CVE-2023-28675 · Severity: low · CVSS 3.1 · Published 2023-04-02

Technologies: org.jenkinsci.plugins:octoperf (Maven). Vendors: Maven.

Executive brief

Jenkins OctoPerf Load Testing Plugin missing permission check allows for unauthorized server connections

Affected products

  • Maven org.jenkinsci.plugins:octoperf

Related threats