Lucene search

K
cvelistOpenTextCVELIST:CVE-2023-4302
HistoryAug 21, 2023 - 10:34 p.m.

CVE-2023-4302 Missing permission checks in Fortify Plugin allow capturing credentials

2023-08-2122:34:30
CWE-862
OpenText
www.cve.org
cve-2023-4302
missing permission check
fortify plugin
jenkins
credentials capture

4.2 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N

5.2 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

13.3%

A missing permission check in Jenkins Fortify Plugin 22.1.38 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.

CNA Affected

[
  {
    "defaultStatus": "unaffected",
    "product": "Jenkins Fortify Plugin",
    "vendor": "Jenkins Project",
    "versions": [
      {
        "lessThanOrEqual": "22.1.38",
        "status": "affected",
        "version": "0",
        "versionType": "maven"
      }
    ]
  }
]

4.2 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N

5.2 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

13.3%

Related for CVELIST:CVE-2023-4302