Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2022-16718
HistoryFeb 17, 2022 - 12:00 a.m.

Jenkins Conjur Secrets Plugin授权问题漏洞

2022-02-1700:00:00
China National Vulnerability Database
www.cnvd.org.cn
6

0.001 Low

EPSS

Percentile

22.0%

Jenkins is a Jenkins open source application. An open source automation server Jenkins provides hundreds of plugins to support building, deploying and automating any project.Jenkins Conjur Secrets Plugin 1.0.11 and earlier versions are vulnerable to an authorization issue that stems from not performing permission checks in HTTP endpoints. An attacker could exploit the vulnerability to enumerate credential ids stored in Jenkins using the Overall Read permission.

CPENameOperatorVersion
jenkins conjur secrets pluginle1.0.11

0.001 Low

EPSS

Percentile

22.0%

Related for CNVD-2022-16718