Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-4g29-r7vj-2rpv

Опубликовано: 19 окт. 2022
Источник: github
Github: Прошло ревью
CVSS3: 4.3

Описание

Jenkins Job Import Plugin allows attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins

Jenkins Job Import Plugin 3.5 and earlier does not perform a permission check in an HTTP endpoint, allowing attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins. An enumeration of credentials IDs in Job Import Plugin 3.6 requires Job Import/Import Jobs permission.

Пакеты

Наименование

org.jenkins-ci.plugins:job-import-plugin

maven
Затронутые версииВерсия исправления

<= 3.5

3.6

EPSS

Процентиль: 74%
0.00845
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-862

Связанные уязвимости

CVSS3: 4.3
nvd
больше 3 лет назад

Jenkins Job Import Plugin 3.5 and earlier does not perform a permission check in an HTTP endpoint, allowing attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.

EPSS

Процентиль: 74%
0.00845
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-862