Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2022-30952

Опубликовано: 17 мая 2022
Источник: redhat
CVSS3: 6.5

Описание

Jenkins Pipeline SCM API for Blue Ocean Plugin 1.25.3 and earlier allows attackers with Job/Configure permission to access credentials with attacker-specified IDs stored in the private per-user credentials stores of any attacker-specified user in Jenkins.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat OpenShift Container Platform 3.11jenkins-2-pluginsWill not fix
OCP-Tools-4.12-RHEL-8jenkins-2-pluginsFixedRHSA-2023:106406.03.2023
Red Hat OpenShift Container Platform 4.10jenkins-2-pluginsFixedRHSA-2023:056008.02.2023
Red Hat OpenShift Container Platform 4.8jenkins-2-pluginsFixedRHSA-2023:001712.01.2023
Red Hat OpenShift Container Platform 4.9jenkins-2-pluginsFixedRHSA-2023:077723.02.2023

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-552->CWE-668
https://bugzilla.redhat.com/show_bug.cgi?id=2119645plugin: User-scoped credentials exposed to other users by Pipeline SCM API for Blue Ocean Plugin

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
nvd
больше 3 лет назад

Jenkins Pipeline SCM API for Blue Ocean Plugin 1.25.3 and earlier allows attackers with Job/Configure permission to access credentials with attacker-specified IDs stored in the private per-user credentials stores of any attacker-specified user in Jenkins.

CVSS3: 5.3
github
больше 3 лет назад

Insufficiently Protected Credentials in Jenkins Pipeline SCM API for Blue Ocean Plugin

6.5 Medium

CVSS3