CVE-2023-2631 is a medium-severity vulnerability affecting Jenkins Code Dx Plugin versions 3.1.0 and earlier, stemming from a missing permission check. This flaw allows authenticated attackers with basic read permissions to force the plugin to connect to an arbitrary URL. While the CVSS score is 4.3, indicating low impact (no confidentiality, integrity, or availability compromise), the vulnerability is not currently known to be actively exploited, nor is public exploit code available. Community discussion and media coverage for this CVE are minimal, aligning with the typical low attention for many vulnerabilities.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 3.1.0CPE matchmatch criteria | cpe:2.3:a:jenkins:code_dx:*:*:*:*:*:jenkins:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.