PT-2023-6484 · Jenkins · Jenkins Warnings Plugin+1

Andrea Chiera

·

Publicado

2023-10-25

·

Atualizado

2023-11-01

·

CVE-2023-46651

CVSS v3.1

6.5

Média

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Jenkins Warnings Plugin versions 10.5.0 and earlier
Description The issue is related to information disclosure, allowing remote attackers to gain unauthorized access to protected information. Specifically, it does not set the appropriate context for credentials lookup, enabling attackers with Item/Configure permission to access and capture credentials they are not entitled to. This allows the use of system-scoped credentials otherwise reserved for the global configuration.
Recommendations For Jenkins Warnings Plugin versions 10.5.0 and earlier, update to version 10.5.1 or later, or apply the backported fix to version 10.4.1, to define the appropriate context for credentials lookup and prevent unauthorized access to credentials. As a temporary workaround, consider restricting access to the credentials lookup functionality for users with Item/Configure permission until the update is applied.

Correção

Insufficiently Protected Credentials

Information Disclosure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2023-07224
CVE-2023-46651
GHSA-66HV-FHCM-7XM7

Produtos afetados

Jenkins
Jenkins Warnings Plugin