CVE-2023-25766: Medium severity jenkins azure credentials vulnerability
Published Feb 15, 2023
·Updated
A missing permission check in Jenkins Azure Credentials Plugin 253.v887e0f9e898b and earlier allows attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.
Affected Software
2 affected componentsFixes available
Jenkins Azure Credentials Jenkins<254.v64da_8176c83a
maven/org.jenkins-ci.plugins:azure-credentials<=253.v887e0f9e898b
254.v64da
Event History
Feb 15, 2023
CVE Published
12:00 AM
Data Sourced
12:00 AM
Description
Advisory Published
03:30 PM
Frequently Asked Questions
1
What is the severity of CVE-2023-25766?
CVE-2023-25766 has a medium severity rating due to missing permission checks that allow credential ID enumeration.
2
How do I fix CVE-2023-25766?
To fix CVE-2023-25766, upgrade the Azure Credentials Plugin to version 254.v64da or later.
3
Who is affected by CVE-2023-25766?
CVE-2023-25766 affects users of Jenkins Azure Credentials Plugin versions up to and including 253.v887e0f9e898b.
4
What can attackers do in CVE-2023-25766?
Attackers with Overall/Read permission can enumerate credentials IDs stored in Jenkins due to insufficient permission checks.
5
Is there a workaround for CVE-2023-25766?
There are no official workarounds for CVE-2023-25766; updating to the latest plugin version is recommended.