CVE-2023-46651Insufficiently Protected Credentials in Jenkins Warnings

Severity
6.5MEDIUMNVD
EPSS
0.1%
top 80.44%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedOct 25

Description

Jenkins Warnings Plugin 10.5.0 and earlier does not set the appropriate context for credentials lookup, allowing attackers with Item/Configure permission to access and capture credentials they are not entitled to. This fix has been backported to 10.4.1.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NExploitability: 2.8 | Impact: 3.6

Affected Packages1 packages

NVDjenkins/warnings10.5.0

🔴Vulnerability Details

3
GHSA
Jenkins Warnings Plugin exposures system-scoped credentials2023-10-25
OSV
Jenkins Warnings Plugin exposures system-scoped credentials2023-10-25
CVEList
CVE-2023-46651: Jenkins Warnings Plugin 102023-10-25

📋Vendor Advisories

1
Jenkins
Jenkins Security Advisory 2023-10-252023-10-25
CVE-2023-46651 — Insufficiently Protected Credentials | cvebase