CVE-2023-41941: Medium severity jenkins aws codecommit trigger vulnerability
Published Sep 6, 2023
·Updated
A missing permission check in Jenkins AWS CodeCommit Trigger Plugin 3.0.12 and earlier allows attackers with Overall/Read permission to enumerate credentials IDs of AWS credentials stored in Jenkins.
Affected Software
2 affected components
maven/org.jenkins-ci.plugins:aws-codecommit-trigger<=3.0.12
Jenkins Aws Codecommit Trigger Jenkins<=3.0.12
Event History
Sep 6, 2023
CVE Published
12:08 PM
Data Sourced
12:08 PM
Description
Data Sourced
via NVD·01:15 PM
DescriptionSeverityWeaknessAffected Software
Advisory Published
via GitHub·03:30 PM
Frequently Asked Questions
1
What is the vulnerability ID for this security issue?
The vulnerability ID for this security issue is CVE-2023-41941.
2
What is the severity level of CVE-2023-41941?
The severity level of CVE-2023-41941 is medium with a CVSS score of 4.3.
3
What is the affected software?
The affected software is Jenkins AWS CodeCommit Trigger Plugin version 3.0.12 and earlier.
4
What is the impact of the vulnerability?
The vulnerability allows attackers with Overall/Read permission to enumerate credentials IDs of AWS credentials stored in Jenkins.
5
Are there any known fixes or patches for this vulnerability?
Yes, please refer to the Jenkins security advisory for details on the fix: https://www.jenkins.io/security/advisory/2023-09-06/#SECURITY-3101%20(1)