Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-w3f7-2qfw-348x

Опубликовано: 13 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 8.8

Описание

Jenkins HipChat Plugin allows credential capture due to incorrect authorization

An improper authorization vulnerability exists in Jenkins HipChat Plugin 2.2.0 and earlier in HipChatNotifier.java that allows attackers with Overall/Read access to send test notifications to an attacker-specified HipChat server with attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins. As of version 2.2.1, this form validation method requires POST requests and Overall/Administer permissions.

Пакеты

Наименование

org.jvnet.hudson.plugins:hipchat

maven
Затронутые версииВерсия исправления

< 2.2.1

2.2.1

EPSS

Процентиль: 44%
0.00214
Низкий

8.8 High

CVSS3

Дефекты

CWE-863

Связанные уязвимости

CVSS3: 8.8
nvd
около 7 лет назад

An improper authorization vulnerability exists in Jenkins HipChat Plugin 2.2.0 and earlier in HipChatNotifier.java that allows attackers with Overall/Read access to send test notifications to an attacker-specified HipChat server with attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.

EPSS

Процентиль: 44%
0.00214
Низкий

8.8 High

CVSS3

Дефекты

CWE-863