A potential vulnerability has been identified in the Micro Focus Dimensions CM Plugin for Jenkins. The vulnerability allows attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.
See the following Jenkins security advisory for details: * https://www.jenkins.io/security/advisory/2023-06-14/ https://www.jenkins.io/security/advisory/2023-06-14/




Advisories
Source ID Title
EUVD EUVD EUVD-2023-1923 A potential vulnerability has been identified in the Micro Focus Dimensions CM Plugin for Jenkins. The vulnerability allows attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins. See the following Jenkins security advisory for details: * https://www.jenkins.io/security/advisory/2023-06-14/ https://www.jenkins.io/security/advisory/2023-06-14/
Github GHSA Github GHSA GHSA-27pr-r7hm-c2rc Missing permission check in Jenkins Dimensions Plugin allows enumerating credentials IDs
Fixes

Solution

Micro Focus has resolved the vulnerability in the latest release of the Dimensions CM Plugin for Jenkins (version 0.9.3.1): https://plugins.jenkins.io/dimensionsscm/ https://plugins.jenkins.io/dimensionsscm/


Workaround

No workaround given by the vendor.

History

Tue, 29 Oct 2024 20:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-863

Mon, 21 Oct 2024 18:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: OpenText

Published:

Updated: 2024-10-29T19:28:56.246Z

Reserved: 2023-05-05T14:42:20.152Z

Link: CVE-2023-32261

cve-icon Vulnrichment

Updated: 2024-08-02T15:10:24.241Z

cve-icon NVD

Status : Modified

Published: 2023-07-19T16:15:09.737

Modified: 2024-11-21T08:02:59.750

Link: CVE-2023-32261

cve-icon Redhat

Severity : Moderate

Publid Date: 2023-06-14T00:00:00Z

Links: CVE-2023-32261 - Bugzilla

cve-icon OpenCVE Enrichment

No data.