Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2022-20616

Опубликовано: 12 янв. 2022
Источник: redhat
CVSS3: 4.3

Описание

Jenkins Credentials Binding Plugin 1.27 and earlier does not perform a permission check in a method implementing form validation, allowing attackers with Overall/Read access to validate if a credential ID refers to a secret file credential and whether it's a zip file.

A missing permissions validation vulnerability was found in the Jenkins Credentials Binding plugin. The form validation method does not perform a permission check which allows attackers with Overall/Read access to validate if a credential ID refers to a secret file credential and whether it’s a zip file.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat OpenShift Container Platform 3.11jenkins-2-pluginsFix deferred
Red Hat OpenShift Container Platform 4jenkins-2-pluginsAffected

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-732
https://bugzilla.redhat.com/show_bug.cgi?id=2044500jenkins-2-plugins/credentials-binding: does not perform a permission check in a method implementing form validation

4.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.3
nvd
около 4 лет назад

Jenkins Credentials Binding Plugin 1.27 and earlier does not perform a permission check in a method implementing form validation, allowing attackers with Overall/Read access to validate if a credential ID refers to a secret file credential and whether it's a zip file.

CVSS3: 4.3
github
около 4 лет назад

Incorrect Permission Assignment for Critical Resource in Jenkins Credentials Binding Plugin

4.3 Medium

CVSS3