Insecure Permission Handling in Jenkins Azure Credentials Plugin
CVE-2023-25768

6.5MEDIUM

Key Information:

Vendor
Jenkins
Vendor
CVE Published:
15 February 2023

Summary

The Azure Credentials Plugin for Jenkins exhibits a vulnerability due to a missing permission check that could allow users with Overall/Read permissions to connect to an attacker-defined web server. This flaw could be exploited by malicious actors to perform unauthorized actions, highlighting the need for urgent updates and security assessments within Jenkins environments utilizing this plugin.

Affected Version(s)

Jenkins Azure Credentials Plugin <= 253.v887e0f9e898b

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.