Security Advisory

CVE-2023-30518

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2023-04-12 17:05:09
Last updated 2025-02-07 18:07:21
Assigner jenkins
State PUBLISHED

Description

A missing permission check in Jenkins Thycotic Secret Server Plugin 1.0.2 and earlier allows attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.