CVE-2023-24436
published 2023-01-26CVE-2023-24436: A missing permission check in Jenkins GitHub Pull Request Builder Plugin 1.42.2 and earlier allows attackers with Overall/Read permission to enumerate…
medium4.3CVSS 3.1
AVNACLPRLUINSUCLINAN
A missing permission check in Jenkins GitHub Pull Request Builder Plugin 1.42.2 and earlier allows attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.
Affected
23 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| jenkins | bearychat_plugin | — | — |
| jenkins | bitbucket_oauth_plugin | — | — |
| jenkins | cisco_spark_notifier_plugin | — | — |
| jenkins | gerrit_trigger_plugin | — | — |
| jenkins | github_pull_request_builder | <= 1.42.2 | — |
| jenkins | github_pull_request_builder_plugin | — | — |
| jenkins | github_pull_request_coverage_status_plugin | — | — |
| jenkins | ids_in_orka_by_macstadium_plugin | — | — |
| jenkins | jira_pipeline_steps_plugin | — | — |
| jenkins | keycloak_authentication_plugin | — | — |
| jenkins | kubernetes_credentials_provider_plugin | — | — |
| jenkins | macstadium_plugin | — | — |
| jenkins | mstest_plugin | — | — |
| jenkins | openid_connect_authentication_plugin | — | — |
| jenkins | openid_plugin | — | — |
| jenkins | orka_by_macstadium_plugin | — | — |
| jenkins | pwauth_security_realm_plugin | — | — |
| jenkins | rabbitmq_consumer_plugin | — | — |
| jenkins | script_security_plugin | — | — |
| jenkins | semantic_versioning_plugin | — | — |
| jenkins | testcomplete_support_plugin | — | — |
| jenkins | testquality_updater_plugin | — | — |
| jenkins_project | jenkins_github_pull_request_builder_plugin | unspecified – 1.42.2 | — |