Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2023-35149

Опубликовано: 14 июн. 2023
Источник: redhat
CVSS3: 4.2

Описание

A missing permission check in Jenkins Digital.ai App Management Publisher Plugin 2.6 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL, capturing credentials stored in Jenkins.

Отчет

The Jenkins Digital.ai App Management Publisher Plugin is not shipped in any of the Red Hat products. Hence, closing as not a bug.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Cryostat 2jenkins-2-pluginsNot affected
Node HealthCheck Operatorjenkins-2-pluginsNot affected
OpenShift Developer Tools and Servicesjenkins-2-pluginsAffected
Red Hat OpenShift Container Platform 3.11jenkins-2-pluginsAffected
Red Hat OpenShift Container Platform 4jenkins-2-pluginsAffected

Показывать по

Дополнительная информация

Статус:

Moderate
https://bugzilla.redhat.com/show_bug.cgi?id=2215094jenkins-2-plugins: ease-plugin: missing permission checks in Digital.ai App Management Publisher Plugin

4.2 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
nvd
больше 2 лет назад

A missing permission check in Jenkins Digital.ai App Management Publisher Plugin 2.6 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL, capturing credentials stored in Jenkins.

CVSS3: 4.2
github
больше 2 лет назад

Jenkins Digital.ai App Management Publisher Plugin missing permission checks

4.2 Medium

CVSS3