CVE-2023-28668
published 2023-04-02CVE-2023-28668: Jenkins Role-based Authorization Strategy Plugin 587.v2872c41fa_e51 and earlier grants permissions even after they've been disabled.
PriorityP348critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
0.83%
53.2th percentile
Jenkins Role-based Authorization Strategy Plugin 587.v2872c41fa_e51 and earlier grants permissions even after they've been disabled.
Affected
15 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| jenkins | absint_a_plugin | — | — |
| jenkins | convert_to_pipeline_plugin | — | — |
| jenkins | cppcheck_plugin | — | — |
| jenkins | crap4j_plugin | — | — |
| jenkins | ids_in_octoperf_load_testing_plugin | — | — |
| jenkins | jacoco_plugin | — | — |
| jenkins | mashup_portlets_plugin | — | — |
| jenkins | octoperf_load_testing_plugin | — | — |
| jenkins | performance_publisher_plugin | — | — |
| jenkins | phabricator_differential_plugin | — | — |
| jenkins | pipeline_aggregator_view_plugin | — | — |
| jenkins | role-based_authorization_strategy | <= 587.v2872c41fa_e51 | — |
| jenkins | role-based_authorization_strategy_plugin | — | — |
| jenkins | visual_studio_code_metrics_plugin | — | — |
| jenkins_project | jenkins_role-based_authorization_strategy_plugin | <= 587.v2872c41fa_e51 | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Jenkins Role-based Authorization Strategy Plugin grants permissions even after they’ve been disabled
osv·2023-04-02
CVE-2023-28668 [MEDIUM] Jenkins Role-based Authorization Strategy Plugin grants permissions even after they’ve been disabled
Jenkins Role-based Authorization Strategy Plugin grants permissions even after they’ve been disabled
Permissions in Jenkins can be enabled and disabled. Some permissions are disabled by default, e.g., Overall/Manage or Item/Extended Read. Disabled permissions cannot be granted directly, only through greater permissions that imply them (e.g., Overall/Administer or Item/Configure).
Role-based Authorization Strategy Plugin 587.v2872c41fa_e51 and earlier grants permissions even after they’ve been disabled.
This allows attackers to have greater access than they’re entitled to after the following operations took place:
A permission is granted to attackers directly or through groups.
The permission is disabled, e.g., through the script console.
Role-based Authorization Strategy Plugin 587.5
GHSA
Jenkins Role-based Authorization Strategy Plugin grants permissions even after they’ve been disabled
ghsa·2023-04-02
CVE-2023-28668 [MEDIUM] CWE-281 Jenkins Role-based Authorization Strategy Plugin grants permissions even after they’ve been disabled
Jenkins Role-based Authorization Strategy Plugin grants permissions even after they’ve been disabled
Permissions in Jenkins can be enabled and disabled. Some permissions are disabled by default, e.g., Overall/Manage or Item/Extended Read. Disabled permissions cannot be granted directly, only through greater permissions that imply them (e.g., Overall/Administer or Item/Configure).
Role-based Authorization Strategy Plugin 587.v2872c41fa_e51 and earlier grants permissions even after they’ve been disabled.
This allows attackers to have greater access than they’re entitled to after the following operations took place:
A permission is granted to attackers directly or through groups.
The permission is disabled, e.g., through the script console.
Role-based Authorization Strategy Plugin 587.5
Jenkins
Jenkins Security Advisory 2023-03-21
vendor_jenkins·2023-03-21·CVSS 9.8
CVE-2023-28668 [CRITICAL] Jenkins Security Advisory 2023-03-21
Title: Jenkins Security Advisory 2023-03-21
Jenkins Security Advisory 2023-03-21
Jenkins Security Home
For Administrators
Overview
Terminology
Vulnerabilities and Scoring
Security Advisories
Security Issues
Advisory Schedule
Vulnerabilities in Plugins
How We Fix Security Issues
For Reporters
Reporting Vulnerabilities
Jenkins CNA
For Maintainers
Overview
Vulnerabilities in Plugins
Jenkins Security Team
About
Contributions
This advisory announces vulnerabilities in the following Jenkins deliverables:
AbsInt a³
Plugin
Convert To Pipeline
Plugin
Cppcheck
Plugin
Crap4J
Plugin
JaCoCo
Plugin
Mashup Portlets
Plugin
OctoPerf Load Testing Plugin
Plugin
OctoPerf Load T
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2023-04-02
Published