Missing Permission Check in Jenkins Azure VM Agents Plugin
CVE-2023-32988
4.3MEDIUM
Summary
The Jenkins Azure VM Agents Plugin contains a vulnerability due to a missing permission check, which can be exploited by unauthorized users with Overall/Read permissions. This flaw allows attackers to list credential IDs stored in Jenkins, potentially compromising sensitive information related to the Jenkins environment. Users are advised to upgrade to the latest version to mitigate this risk. For detailed information, refer to the Jenkins Security Advisory.
Affected Version(s)
Jenkins Azure VM Agents Plugin 0 <= 852.v8d35f0960a_43
References
CVSS V3.1
Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved