Lucene search

K
cveQualysCVE-2023-4777
HistorySep 08, 2023 - 9:15 a.m.

CVE-2023-4777

2023-09-0809:15:08
CWE-732
Qualys
web.nvd.nist.gov
29
cve
qualys
container scanning
connector plugin
jenkins
security flaw
permissions issue

CVSS3

4.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

AI Score

4.5

Confidence

High

EPSS

0.001

Percentile

21.7%

An incorrect permission check in Qualys Container Scanning Connector Plugin 1.6.2.6 and earlier allows attackers with global Item/Configure permission (while lacking Item/Configure permission on any particular job) to enumerate credentials IDs of credentials stored in Jenkins and to connect to an attacker-specified URL using attacker-specified credentials IDs, capturing credentials stored in Jenkins.

Affected configurations

Nvd
Node
qualyscontainer_scanning_connectorRange<1.6.2.7
VendorProductVersionCPE
qualyscontainer_scanning_connector*cpe:2.3:a:qualys:container_scanning_connector:*:*:*:*:*:*:*:*

CNA Affected

[
  {
    "defaultStatus": "unaffected",
    "product": "Container Scanning Connector Jenkins Plugin",
    "vendor": "Qualys,Inc. ",
    "versions": [
      {
        "lessThanOrEqual": "1.6.0.1",
        "status": "affected",
        "version": "1.6.2.6",
        "versionType": "custom"
      }
    ]
  }
]

CVSS3

4.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

AI Score

4.5

Confidence

High

EPSS

0.001

Percentile

21.7%

Related for CVE-2023-4777