CVE-2023-4777

CVSS V2 None CVSS V3 None
Description
An incorrect permission check in Qualys Container Scanning Connector Plugin 1.6.2.6 and earlier allows attackers with global Item/Configure permission (while lacking Item/Configure permission on any particular job) to enumerate credentials IDs of credentials stored in Jenkins and to connect to an attacker-specified URL using attacker-specified credentials IDs, capturing credentials stored in Jenkins. 
Overview
  • CVE ID
  • CVE-2023-4777
  • Assigner
  • Qualys
  • Vulnerability Status
  • PUBLISHED
  • Published Version
  • 2023-09-08T08:42:35.645Z
  • Last Modified Date
  • 2023-09-08T08:42:35.645Z
References
Reference URL Reference Tags
https://www.qualys.com/security-advisories/ vendor-advisory
History
Created Old Value New Value Data Type Notes
2024-06-24 19:59:14 Added to TrackCVE