PT-2023-6484 · Jenkins · Jenkins Warnings Plugin+1

Andrea Chiera

·

Published

2023-10-25

·

Updated

2023-11-01

·

CVE-2023-46651

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Jenkins Warnings Plugin versions 10.5.0 and earlier
Description The issue is related to information disclosure, allowing remote attackers to gain unauthorized access to protected information. Specifically, it does not set the appropriate context for credentials lookup, enabling attackers with Item/Configure permission to access and capture credentials they are not entitled to. This allows the use of system-scoped credentials otherwise reserved for the global configuration.
Recommendations For Jenkins Warnings Plugin versions 10.5.0 and earlier, update to version 10.5.1 or later, or apply the backported fix to version 10.4.1, to define the appropriate context for credentials lookup and prevent unauthorized access to credentials. As a temporary workaround, consider restricting access to the credentials lookup functionality for users with Item/Configure permission until the update is applied.

Fix

Insufficiently Protected Credentials

Information Disclosure

Weakness Enumeration

Related Identifiers

BDU:2023-07224
CVE-2023-46651
GHSA-66HV-FHCM-7XM7

Affected Products

Jenkins
Jenkins Warnings Plugin