First published: Wed Aug 16 2023(Updated: )
A missing permission check in Jenkins Delphix Plugin 3.0.2 and earlier allows attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.
Credit: jenkinsci-cert@googlegroups.com jenkinsci-cert@googlegroups.com jenkinsci-cert@googlegroups.com
Affected Software | Affected Version | How to fix |
---|---|---|
Jenkins Delphix | <=3.0.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2023-40344.
CVE-2023-40344 has a severity rating of 4.3, which is considered medium.
CVE-2023-40344 allows attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins, potentially leading to credential capture and misuse.
Jenkins Delphix Plugin versions up to and including 3.0.2 are affected by CVE-2023-40344.
To fix CVE-2023-40344, you should upgrade Jenkins Delphix Plugin to version 3.0.3 or later.