CVE-2023-37951Insufficiently Protected Credentials in Project Jenkins Mabl Plugin

Severity
6.5MEDIUMNVD
EPSS
0.1%
top 75.73%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 12

Description

Jenkins mabl Plugin 0.0.46 and earlier does not set the appropriate context for credentials lookup, allowing attackers with Item/Configure permission to access and capture credentials they are not entitled to.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NExploitability: 2.8 | Impact: 3.6

Affected Packages2 packages

🔴Vulnerability Details

3
GHSA
Jenkins mabl Plugin vulnerable to exposure of system-scooped credentials2023-07-12
CVEList
CVE-2023-37951: Jenkins mabl Plugin 02023-07-12
OSV
Jenkins mabl Plugin vulnerable to exposure of system-scooped credentials2023-07-12

📋Vendor Advisories

1
Jenkins
Jenkins Security Advisory 2023-07-122023-07-12
CVE-2023-37951 — Insufficiently Protected Credentials | cvebase