CVE-2023-49653Insufficiently Protected Credentials in Project Jenkins Jira Plugin

Severity
6.5MEDIUMNVD
EPSS
0.1%
top 80.44%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 29

Description

Jenkins Jira Plugin 3.11 and earlier does not set the appropriate context for credentials lookup, allowing attackers with Item/Configure permission to access and capture credentials they are not entitled to.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NExploitability: 2.8 | Impact: 3.6

Affected Packages2 packages

🔴Vulnerability Details

3
CVEList
CVE-2023-49653: Jenkins Jira Plugin 32023-11-29
GHSA
Jenkins Jira Plugin vulnerable to exposure of system-scoped credentials2023-11-29
OSV
Jenkins Jira Plugin vulnerable to exposure of system-scoped credentials2023-11-29

📋Vendor Advisories

1
Jenkins
Jenkins Security Advisory 2023-11-292023-11-29
CVE-2023-49653 — Insufficiently Protected Credentials | cvebase