Jenkins Pipeline SCM API for Blue Ocean Plugin 1.25.3 and earlier allows attackers with Job/Configure permission to access credentials with attacker-specified IDs stored in the private per-user credentials stores of any attacker-specified user in Jenkins.
Advisories
Source ID Title
EUVD EUVD EUVD-2022-3909 Jenkins Pipeline SCM API for Blue Ocean Plugin 1.25.3 and earlier allows attackers with Job/Configure permission to access credentials with attacker-specified IDs stored in the private per-user credentials stores of any attacker-specified user in Jenkins.
Github GHSA Github GHSA GHSA-g74w-93cp-5p3p Insufficiently Protected Credentials in Jenkins Pipeline SCM API for Blue Ocean Plugin
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: jenkins

Published:

Updated: 2024-08-03T07:03:39.865Z

Reserved: 2022-05-16T00:00:00

Link: CVE-2022-30952

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2022-05-17T15:15:09.293

Modified: 2024-11-21T07:03:37.153

Link: CVE-2022-30952

cve-icon Redhat

Severity : Moderate

Publid Date: 2022-05-17T00:00:00Z

Links: CVE-2022-30952 - Bugzilla

cve-icon OpenCVE Enrichment

No data.