Improper Permission Check in Jenkins Azure VM Agents Plugin by Jenkins
CVE-2023-32990
6.5MEDIUM
Key Information:
- Vendor
Jenkins
- Vendor
- CVE Published:
- 16 May 2023
What is CVE-2023-32990?
A vulnerability exists in the Jenkins Azure VM Agents Plugin that permits authenticated attackers with Overall/Read permission to connect to arbitrary Azure Cloud servers. This is achieved by exploiting a missing permission check that allows the use of attacker-specified credential IDs. This flaw can lead to unauthorized access to sensitive cloud resources, potentially compromising the security of the deployed environment. Organizations using this plugin should assess their configurations and apply any necessary patches as soon as possible to mitigate this risk.
Affected Version(s)
Jenkins Azure VM Agents Plugin 0 <= 852.v8d35f0960a_43