CVE-2023-28675
Description
A missing permission check in Jenkins OctoPerf Load Testing Plugin 4.5.2 and earlier allows attackers to connect to a configured Octoperf server with attacker-specified credentials.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
A missing permission check in Jenkins OctoPerf Load Testing Plugin 4.5.2 and earlier allows attackers to connect to a configured Octoperf server with attacker-specified credentials.
Vulnerability
Overview
The Jenkins OctoPerf Load Testing Plugin, versions 4.5.2 and earlier, contains a missing permission check vulnerability. This flaw allows an attacker to connect to a previously configured Octoperf server using credentials that the attacker specifies, without requiring proper authorization [1][2].
Exploitation and
Attack Surface
Exploitation of this vulnerability does not require authentication to Jenkins, as the permission check is missing entirely. An attacker who can access a Jenkins instance with the plugin installed can leverage this to modify the connection credentials to the Octoperf server. No specific privileges are needed, making this a low-complexity attack vector [1][2].
Impact
Successful exploitation enables an attacker to control the credentials used for the connection to the Octoperf load testing server. This could lead to unauthorized use of the Octoperf service, potential data exposure, and a loss of integrity in the load testing configuration [1][2].
Mitigation
The Jenkins security advisory (2023-03-21) recommends upgrading the OctoPerf Load Testing Plugin to version 4.5.3 or later, which includes the necessary permission check fix. Users should update their plugin as soon as possible to mitigate this vulnerability [1].
AI Insight generated on May 20, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.jenkinsci.plugins:octoperfMaven | < 4.5.3 | 4.5.3 |
Affected products
2- Range: 0
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- github.com/advisories/GHSA-p3w6-3f7f-pm98ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2023-28675ghsaADVISORY
- www.jenkins.io/security/advisory/2023-03-21/ghsavendor-advisoryWEB
News mentions
1- Jenkins Security Advisory 2023-03-21Jenkins Security Advisories · Mar 21, 2023