Missing Permission Check in Jenkins RabbitMQ Consumer Plugin
CVE-2023-24448
6.5MEDIUM
Key Information:
- Vendor
- Jenkins
- Vendor
- CVE Published:
- 26 January 2023
Summary
A significant security concern exists in the RabbitMQ Consumer Plugin for Jenkins, where a missing permission check allows users with Overall/Read permissions to connect to an external AMQP(S) URL. This vulnerability enables attackers to specify both the URL and the credentials (username and password), potentially leading to unauthorized access to sensitive information. Users are urged to upgrade to the latest version to mitigate this risk.
Affected Version(s)
Jenkins RabbitMQ Consumer Plugin <= 2.8
References
CVSS V3.1
Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved