First published: Wed Aug 16 2023(Updated: )
Jenkins Delphix Plugin 3.0.2 and earlier does not set the appropriate context for credentials lookup, allowing attackers with Overall/Read permission to access and capture credentials they are not entitled to.
Credit: jenkinsci-cert@googlegroups.com jenkinsci-cert@googlegroups.com jenkinsci-cert@googlegroups.com
Affected Software | Affected Version | How to fix |
---|---|---|
Jenkins Delphix | <=3.0.2 | |
maven/org.jenkins-ci.plugins:delphix | <3.0.3 | 3.0.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID of Jenkins Delphix Plugin is CVE-2023-40345.
The severity of CVE-2023-40345 is medium with a CVSS score of 6.5.
Jenkins Delphix Plugin 3.0.2 and earlier does not set the appropriate context for credentials lookup, allowing the use of System-scoped credentials otherwise reserved for the global configuration.
Jenkins Delphix Plugin versions up to and including 3.0.2 are affected by CVE-2023-40345.
It is recommended to upgrade to version 3.0.3 of Jenkins Delphix Plugin to fix the vulnerability.