CVE-2023-49653: Medium severity jenkins vulnerability
Jenkins Jira Plugin 3.11 and earlier does not set the appropriate context for credentials lookup, allowing attackers with Item/Configure permission to access and capture credentials they are not entitled to.
Other sources
Jenkins Jira Plugin 3.11 and earlier does not set the appropriate context for credentials lookup, allowing the use of system-scoped credentials otherwise reserved for the global configuration.
This allows attackers with Item/Configure permission to access and capture credentials they are not entitled to.
Jira Plugin 3.12 defines the appropriate context for credentials lookup.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-49653?
The severity of CVE-2023-49653 is medium with a CVSS score of 4.3.
How does CVE-2023-49653 affect Jenkins Jira Plugin?
CVE-2023-49653 affects Jenkins Jira Plugin version 3.11 and earlier.
What is the remedy for CVE-2023-49653?
The remedy for CVE-2023-49653 is to upgrade to version 3.12 of the Jenkins Jira Plugin.
What are the references for CVE-2023-49653?
The references for CVE-2023-49653 are [1](https://www.jenkins.io/security/advisory/2023-11-29/#SECURITY-3225), [2](http://www.openwall.com/lists/oss-security/2023/11/29/1), and [3](https://nvd.nist.gov/vuln/detail/CVE-2023-49653).