Credential Exposure in GitHub Branch Source by CloudBees
CVE-2017-1000087
4.3MEDIUM
Summary
The GitHub Branch Source Plugin by CloudBees exposes a list of valid credential IDs without proper permission checks. Users with Overall/Read permissions can access these IDs, posing a security risk as unauthorized users may exploit this information to retrieve sensitive credentials and gain unauthorized access through related vulnerabilities.
References
CVSS V3.1
Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved