Description
Jenkins Job Import Plugin 3.5 and earlier does not perform a permission check in an HTTP endpoint, allowing attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:NExploitability: 2.8 | Impact: 1.4Attack Vector: Network
Complexity: Low
Privileges: Low
User Interaction: None
Scope: Unchanged
Confidentiality: Low
Integrity: None
Availability: None
Affected Packages3 packages
🔴Vulnerability Details
3OSVJenkins Job Import Plugin allows attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins↗2022-10-19 ▶ CVEListCVE-2022-43413: Jenkins Job Import Plugin 3↗2022-10-19 ▶ GHSAJenkins Job Import Plugin allows attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins↗2022-10-19 ▶ 📋Vendor Advisories
1JenkinsJenkins Security Advisory 2022-10-19↗2022-10-19 ▶