First published: Tue Jan 24 2023(Updated: )
A missing permission check in Jenkins Orka by MacStadium Plugin 1.31 and earlier allows attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.
Credit: jenkinsci-cert@googlegroups.com jenkinsci-cert@googlegroups.com jenkinsci-cert@googlegroups.com
Affected Software | Affected Version | How to fix |
---|---|---|
Jenkins Orka By Macstadium | <1.32 | |
maven/io.jenkins.plugins:macstadium-orka | <1.32 | 1.32 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2023-24431 is medium with a CVSS score of 4.3.
CVE-2023-24431 is a vulnerability in Jenkins Orka by MacStadium Plugin 1.31 and earlier that allows attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.
An attacker with Overall/Read permission can exploit CVE-2023-24431 to enumerate credentials IDs of credentials stored in Jenkins.
The affected software for CVE-2023-24431 is Jenkins Orka by MacStadium Plugin 1.31 and earlier.
Yes, a fix is available for CVE-2023-24431. It is recommended to update to version 1.32 or later of the Jenkins Orka by MacStadium Plugin.