CVE-2023-40344: Medium severity jenkins delphix vulnerability
A missing permission check in Jenkins Delphix Plugin 3.0.2 and earlier allows attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.
Other sources
Jenkins Delphix Plugin 3.0.2 and earlier does not perform a permission check in an HTTP endpoint.
This allows attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins. Those can be used as part of an attack to capture the credentials using another vulnerability.
An enumeration of credentials IDs in Delphix Plugin 3.0.3 requires the appropriate permissions.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID of this issue?
The vulnerability ID is CVE-2023-40344.
What is the severity rating of CVE-2023-40344?
CVE-2023-40344 has a severity rating of 4.3, which is considered medium.
How does CVE-2023-40344 impact Jenkins Delphix Plugin?
CVE-2023-40344 allows attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins, potentially leading to credential capture and misuse.
What versions of Jenkins Delphix Plugin are affected by CVE-2023-40344?
Jenkins Delphix Plugin versions up to and including 3.0.2 are affected by CVE-2023-40344.
How can I fix CVE-2023-40344?
To fix CVE-2023-40344, you should upgrade Jenkins Delphix Plugin to version 3.0.3 or later.