Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2023-32262

Опубликовано: 14 июн. 2023
Источник: redhat
CVSS3: 4.3

Описание

A potential vulnerability has been identified in the Micro Focus Dimensions CM Plugin for Jenkins. The vulnerability allows attackers with Item/Configure permission to access and capture credentials they are not entitled to. See the following Jenkins security advisory for details: * https://www.jenkins.io/security/advisory/2023-06-14/ https://www.jenkins.io/security/advisory/2023-06-14/

Отчет

The Jenkins Dimensions Plugin is not shipped in any of the Red Hat products. Hence, closing as not a bug.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Cryostat 2jenkins-2-pluginsNot affected
Node HealthCheck Operatorjenkins-2-pluginsNot affected
OpenShift Developer Tools and Servicesjenkins-2-pluginsAffected
Red Hat OpenShift Container Platform 3.11jenkins-2-pluginsAffected
Red Hat OpenShift Container Platform 4jenkins-2-pluginsAffected

Показывать по

Дополнительная информация

Статус:

Moderate
https://bugzilla.redhat.com/show_bug.cgi?id=2215105jenkins-2-plugins: dimensionsscm: Exposure of system-scoped credentials in Dimensions Plugin

4.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.3
nvd
больше 2 лет назад

A potential vulnerability has been identified in the Micro Focus Dimensions CM Plugin for Jenkins. The vulnerability allows attackers with Item/Configure permission to access and capture credentials they are not entitled to. See the following Jenkins security advisory for details: * https://www.jenkins.io/security/advisory/2023-06-14/ https://www.jenkins.io/security/advisory/2023-06-14/

CVSS3: 4.3
github
больше 2 лет назад

Exposure of system-scoped credentials in Jenkins Dimensions Plugin

CVSS3: 4.3
fstec
больше 2 лет назад

Уязвимость плагина Dimensions сервера автоматизации Jenkins, связанная с недостаточной защитой служебных данных, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

4.3 Medium

CVSS3