cbcvebase.
CVE-2023-46651
published 2023-10-25

CVE-2023-46651: Jenkins Warnings Plugin 10.5.0 and earlier does not set the appropriate context for credentials lookup, allowing attackers with Item/Configure permission to…

PriorityP336medium6.5CVSS 3.1
AVNACLPRLUINSUCHINAN
EPSS
0.61%
45.0th percentile
Jenkins Warnings Plugin 10.5.0 and earlier does not set the appropriate context for credentials lookup, allowing attackers with Item/Configure permission to access and capture credentials they are not entitled to. This fix has been backported to 10.4.1.

Affected

10 ranges
VendorProductVersion rangeFixed in
jenkinscloudbees_cd_plugin
jenkinsedgewall_trac_plugin
jenkinsgithub_plugin
jenkinsgogs_plugin
jenkinsmsteams_webhook_trigger_plugin
jenkinsmultibranch_scan_webhook_trigger_plugin
jenkinsnon-constant_time_webhook_token_comparison_in_gogs_plugin
jenkinswarnings<= 10.5.0
jenkinswarnings_plugin
jenkinszanata_plugin
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.