Credential Exposure in GitHub Branch Source by CloudBees
CVE-2017-1000087

4.3MEDIUM

Key Information:

Vendor
Jenkins
Vendor
CVE Published:
5 October 2017

Summary

The GitHub Branch Source Plugin by CloudBees exposes a list of valid credential IDs without proper permission checks. Users with Overall/Read permissions can access these IDs, posing a security risk as unauthorized users may exploit this information to retrieve sensitive credentials and gain unauthorized access through related vulnerabilities.

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.