CVE-2023-4777: Incorrect Permission Assignment on Qualys Container Scanning Connector Plugin 1.6.2.6 and earlier
An incorrect permission check in Qualys Container Scanning Connector Plugin 1.6.2.6 and earlier allows attackers with global Item/Configure permission (while lacking Item/Configure permission on any particular job) to enumerate credentials IDs of credentials stored in Jenkins and to connect to an attacker-specified URL using attacker-specified credentials IDs, capturing credentials stored in Jenkins.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2023-4777.
What is the affected software?
The affected software is Qualys Container Scanning Connector Plugin 1.6.2.6 and earlier.
What is the severity of CVE-2023-4777?
The severity of CVE-2023-4777 is medium with a CVSS score of 4.3.
How can an attacker exploit CVE-2023-4777?
An attacker with global Item/Configure permission (while lacking Item/Configure permission on any particular job) can exploit CVE-2023-4777 to enumerate credentials IDs and connect to an affected system.
Is there a fix available for CVE-2023-4777?
Yes, a fix is available for CVE-2023-4777. It is recommended to update Qualys Container Scanning Connector Plugin to version 1.6.2.7 or later.