Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-wwww-xvm2-62w7

Опубликовано: 16 авг. 2023
Источник: github
Github: Прошло ревью
CVSS3: 4.3

Описание

Jenkins Delphix Plugin vulnerable to exposure of system-scoped credentials

Jenkins Delphix Plugin 3.0.2 and earlier does not set the appropriate context for credentials lookup, allowing the use of System-scoped credentials otherwise reserved for the global configuration.

This allows attackers with Overall/Read permission to access and capture credentials they are not entitled to.

Delphix Plugin 3.0.3 defines the appropriate context for credentials lookup.

Пакеты

Наименование

org.jenkins-ci.plugins:delphix

maven
Затронутые версииВерсия исправления

< 3.0.3

3.0.3

EPSS

Процентиль: 33%
0.00127
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-522

Связанные уязвимости

CVSS3: 6.5
nvd
больше 2 лет назад

Jenkins Delphix Plugin 3.0.2 and earlier does not set the appropriate context for credentials lookup, allowing attackers with Overall/Read permission to access and capture credentials they are not entitled to.

EPSS

Процентиль: 33%
0.00127
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-522