Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-3m8w-442m-3p2q

Опубликовано: 24 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 4.3

Описание

Jenkins Artifactory Plugin missing permission check

Jenkins Artifactory Plugin provides a list of applicable credential IDs to allow users configuring the plugin to select the one to use.

This functionality does not correctly check permissions, allowing any user with Overall/Read permission to get a list of valid credentials IDs. Those can be used as part of an attack to capture the credentials using another vulnerability.

As of publication of this advisory, no release containing a fix is available.

Пакеты

Наименование

org.jenkins-ci.plugins:artifactory

maven
Затронутые версииВерсия исправления

<= 3.2.2

Отсутствует

EPSS

Процентиль: 50%
0.00264
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-862

Связанные уязвимости

CVSS3: 4.3
nvd
больше 6 лет назад

A missing permission check in Jenkins Artifactory Plugin 3.2.3 and earlier in various 'fillCredentialsIdItems' methods allowed users with Overall/Read access to enumerate credentials ID of credentials stored in Jenkins.

EPSS

Процентиль: 50%
0.00264
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-862