Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-3m3f-2323-64m7

Опубликовано: 24 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 6.5

Описание

Incorrect permission checks in Jenkins Config File Provider Plugin allow enumerating credentials IDs

Jenkins Config File Provider Plugin 3.7.0 and earlier does not correctly perform permission checks in several HTTP endpoints.

This allows attackers with global Job/Configure permission to enumerate system-scoped credentials IDs of credentials stored in Jenkins. Those can be used as part of an attack to capture the credentials using another vulnerability.

An enumeration of system-scoped credentials IDs in Jenkins Config File Provider Plugin 3.7.1 requires Overall/Administer permission.

Пакеты

Наименование

org.jenkins-ci.plugins:config-file-provider

maven
Затронутые версииВерсия исправления

<= 3.7.0

3.7.1

EPSS

Процентиль: 74%
0.00832
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-863

Связанные уязвимости

CVSS3: 4.3
redhat
почти 5 лет назад

Jenkins Config File Provider Plugin 3.7.0 and earlier does not correctly perform permission checks in several HTTP endpoints, allowing attackers with global Job/Configure permission to enumerate system-scoped credentials IDs of credentials stored in Jenkins.

CVSS3: 6.5
nvd
почти 5 лет назад

Jenkins Config File Provider Plugin 3.7.0 and earlier does not correctly perform permission checks in several HTTP endpoints, allowing attackers with global Job/Configure permission to enumerate system-scoped credentials IDs of credentials stored in Jenkins.

EPSS

Процентиль: 74%
0.00832
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-863