Jenkins Config File Provider Plugin 3.7.0 and earlier does not correctly perform permission checks in several HTTP endpoints, allowing attackers with global Job/Configure permission to enumerate system-scoped credentials IDs of credentials stored in Jenkins.
CVSS Details
- CVSS 3.1 Base Score: 6.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Redhat Openshift | — | Upgrade openvswitch2.15Upgrade python-oslo-dbUpgrade jenkins-2-pluginsUpgrade python-kubernetesUpgrade ignitionUpgrade python-oslo-i18nUpgrade openstack-ironic-inspectorUpgrade atomic-openshift-service-idlerUpgrade podmanUpgrade python-debtcollectorUpgrade python-oslo-serviceUpgrade ironic-imagesUpgrade ironic-images-ipa-x86_64Upgrade python-pyrsistentUpgrade ovn2.13Upgrade python-openstacksdkUpgrade ironic-images-ipa-ppc64leUpgrade openshift-kuryrUpgrade python-oslo-upgradecheckUpgrade openshift-ansibleUpgrade python-oslo-configUpgrade python-ironic-prometheus-exporterUpgrade openshiftUpgrade python-oslo-utilsUpgrade haproxyUpgrade jenkinsUpgrade python-oslo-policyUpgrade python-oslo-concurrencyUpgrade python-ironic-libUpgrade ostreeUpgrade python-stevedoreUpgrade python-oslo-contextUpgrade rust-afterburnUpgrade console-login-helper-messagesUpgrade python-openshiftUpgrade python-eventletUpgrade openstack-ironic-python-agentUpgrade cri-oUpgrade redhat-release-coreosUpgrade coreos-installerUpgrade rteval-loadsUpgrade python-oslo-serializationUpgrade python-sushy-oem-idracUpgrade python-toozUpgrade cri-toolsUpgrade toolboxUpgrade python-oslo-logUpgrade openstack-ironicUpgrade openshift-clientsUpgrade kata-containersUpgrade butaneUpgrade python-hardwareUpgrade python-sushyUpgrade python-keystoneauth1Upgrade python-jsonschemaUpgrade runc | Jun 2, 2021 | Apr 21, 2021 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub