Lucene search

K
osvGoogleOSV:GHSA-FJH2-QHFH-RVFC
HistoryMay 13, 2022 - 1:50 a.m.

Jenkins Maven Artifact ChoiceListProvider (Nexus) Plugin CSRF vulnerability and missing permission checks

2022-05-1301:50:55
Google
osv.dev
5
jenkins
maven
artifact
choicelistprovider
nexus
plugin
csrf
vulnerability
missing permission checks
sensitive information
artifactory
credentials
jenkins.

AI Score

6.1

Confidence

High

EPSS

0.001

Percentile

22.0%

An exposure of sensitive information vulnerability exists in Jenkins Maven Artifact ChoiceListProvider (Nexus) Plugin 1.3.1 and earlier in ArtifactoryChoiceListProvider.java, NexusChoiceListProvider.java, Nexus3ChoiceListProvider.java that allows attackers to capture credentials with a known credentials ID stored in Jenkins.

AI Score

6.1

Confidence

High

EPSS

0.001

Percentile

22.0%

Related for OSV:GHSA-FJH2-QHFH-RVFC