Beveiligingsadvies

CVE-2023-30518

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2023-04-12 17:05:09
Laatst bijgewerkt 2025-02-07 18:07:21
Toegewezen door jenkins
CVSS-score 4.3
Status PUBLISHED

Beschrijving

A missing permission check in Jenkins Thycotic Secret Server Plugin 1.0.2 and earlier allows attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.