CyberRota Analysis
AI-GeneratedThe External Workspace Manager Plugin in Jenkins versions 1.4.1 and earlier lacks proper permission checks, enabling users with Overall/Read permissions to access unauthorized files in externally-managed workspaces. This vulnerability could lead to sensitive information disclosure, making it critical for Jenkins administrators and organizations using this plugin to prioritize updates to version 1.4.2 or later to mitigate potential data breaches.
Original NVD Description
Jenkins External Workspace Manager Plugin 1.4.1 and earlier does not perform a permission check (1.4.0 and earlier) or performs an improper permission check (1.4.1) when providing access to externally-managed workspaces through the workspace browser, allowing attackers with Overall/Read permission to read files in workspaces they are not authorized to access.