Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Sat, 30 May 2026 23:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Jenkins Project
Jenkins Project jenkins Appspider Plugin |
|
| Vendors & Products |
Jenkins Project
Jenkins Project jenkins Appspider Plugin |
Thu, 28 May 2026 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Jenkins
Jenkins appspider |
|
| CPEs | cpe:2.3:a:jenkins:appspider:*:*:*:*:*:jenkins:*:* | |
| Vendors & Products |
Jenkins
Jenkins appspider |
Wed, 27 May 2026 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Jenkins AppSpider Plugin Enables Unchecked Outbound Connections |
Wed, 27 May 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-269 | |
| Metrics |
cvssV3_1
|
Wed, 27 May 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Jenkins AppSpider Plugin 1.0.17 and earlier does not perform a permission check in a method implementing form validation, allowing attackers with Overall/Read permission to connect to an attacker-specified URL. | |
| References |
|
Status: PUBLISHED
Assigner: jenkins
Published:
Updated: 2026-05-27T15:23:37.921Z
Reserved: 2026-05-26T14:50:46.813Z
Link: CVE-2026-48923
Updated: 2026-05-27T15:23:17.126Z
Status : Analyzed
Published: 2026-05-27T15:16:31.950
Modified: 2026-06-17T10:55:24.373
Link: CVE-2026-48923
No data.
OpenCVE Enrichment
Updated: 2026-05-30T21:21:53Z