CVE 5.3 MEDIUM

Missing authorization in BlazeMeter Jenkins Plugin_CVE-2025-13472

5.3 / 10
MEDIUM
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N

Description

A fix was made in BlazeMeter Jenkins Plugin version 4.27 to allow users only with certain permissions to see the list of available resources like credential IDs, bzm workspaces and bzm project Ids. Prior to this fix, anyone could see this list as a dropdown on the Jenkins UI.

Basic Information

ID CVE-2025-13472
Source Perforce
Published Dec 3, 2025 at 08:42
Modified Dec 3, 2025 at 08:45

Affected Product

Vendor Perforce
Product BlazeMeter
Affected Versions Perforce BlazeMeter 0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.