CVE-2023-32988

CVSS v3.1 4.3 (Medium)
43% Progress
EPSS 0.05 % (18th)
0.05% Progress
Affected Products 1
Advisories 2

A missing permission check in Jenkins Azure VM Agents Plugin 852.v8d35f0960a_43 and earlier allows attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.

Weaknesses
CWE-522
Insufficiently Protected Credentials
CVE Status
PUBLISHED
CNA
Jenkins Project
Published Date
2023-05-16 16:15:11
(16 months ago)
Updated Date
2023-05-25 00:32:30
(16 months ago)

Affected Products

Loading...
Loading...
Loading...

Configuration #1

    CPE23 From Up To
  Jenkins Azure Vm Agents for Jenkins 852.v8d35f0960a_43 and prior versions cpe:2.3:a:jenkins:azure_vm_agents::*:*:*:*:jenkins <= 852.v8d35f0960a_43
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...