CVE-2023-25768: Medium severity jenkins azure credentials vulnerability
Published Feb 15, 2023
·Updated
A missing permission check in Jenkins Azure Credentials Plugin 253.v887e0f9e898b and earlier allows attackers with Overall/Read permission to connect to an attacker-specified web server.
Affected Software
2 affected componentsFixes available
Jenkins Azure Credentials Jenkins<254.v64da_8176c83a
maven/org.jenkins-ci.plugins:azure-credentials<=253.v887e0f9e898b
254.v64da_8176c83a
Event History
Feb 15, 2023
CVE Published
12:00 AM
Data Sourced
12:00 AM
Description
Advisory Published
03:30 PM
Frequently Asked Questions
1
What is the severity of CVE-2023-25768?
CVE-2023-25768 is categorized as a medium severity vulnerability.
2
How do I fix CVE-2023-25768?
To resolve CVE-2023-25768, upgrade to Jenkins Azure Credentials Plugin version 254.v64da_8176c83a or later.
3
Who is affected by CVE-2023-25768?
CVE-2023-25768 affects users of Jenkins Azure Credentials Plugin versions 253.v887e0f9e898b and earlier.
4
What does CVE-2023-25768 exploit?
CVE-2023-25768 exploits a missing permission check that allows attackers with Overall/Read permission to connect to arbitrary web servers.
5
What software components are involved in CVE-2023-25768?
CVE-2023-25768 involves the Jenkins Azure Credentials Plugin.