Missing Authorization in Jenkins Azure Credentials Plugin
Moderate severity
GitHub Reviewed
Published
Feb 15, 2023
to the GitHub Advisory Database
•
Updated Jan 4, 2024
Package
Affected versions
<= 253.v887e0f9e898b
Patched versions
254.v64da
Description
Published by the National Vulnerability Database
Feb 15, 2023
Published to the GitHub Advisory Database
Feb 15, 2023
Reviewed
Feb 15, 2023
Last updated
Jan 4, 2024
A missing permission check in Jenkins Azure Credentials Plugin 253.v887e0f9e898b and earlier allows attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.
References