CVE-2023-41947
https://notcve.org/view.php?id=CVE-2023-41947
A missing permission check in Jenkins Frugal Testing Plugin 1.1 and earlier allows attackers with Overall/Read permission to connect to Frugal Testing using attacker-specified credentials. Una comprobación de permisos faltante en el complemento Jenkins Frugal Testing 1.1 y versiones anteriores permite a los atacantes con permiso Overall/Read conectarse a Frugal Testing utilizando credenciales especificadas por el atacante. • http://www.openwall.com/lists/oss-security/2023/09/06/9 https://www.jenkins.io/security/advisory/2023-09-06/#SECURITY-3082 • CWE-862: Missing Authorization •
CVE-2023-41946
https://notcve.org/view.php?id=CVE-2023-41946
A cross-site request forgery (CSRF) vulnerability in Jenkins Frugal Testing Plugin 1.1 and earlier allows attackers to connect to Frugal Testing using attacker-specified credentials, and to retrieve test IDs and names from Frugal Testing, if a valid credential corresponds to the attacker-specified username. Una vulnerabilidad de Cross-Site Request Forgery (CSRF) en el complemento Jenkins Frugal Testing 1.1 y versiones anteriores permite a los atacantes conectarse a Frugal Testing utilizando credenciales especificadas por el atacante y recuperar ID y nombres de prueba de Frugal Testing, si una credencial válida corresponde al nombre de usuario especificado por el atacante. • http://www.openwall.com/lists/oss-security/2023/09/06/9 https://www.jenkins.io/security/advisory/2023-09-06/#SECURITY-3082 • CWE-352: Cross-Site Request Forgery (CSRF) •