LOW✓ PATCH🇬🇧 English

CVE-2023-49652

CVSS 2.7v3.1pub. 2023-11-29upd. 2024-11-21

Nieprawidłowe sprawdzenie uprawnień w wtyczce Jenkins Google Compute Engine Plugin w wersji 4.550.vb_327fca_3db_11 i wcześniejszych pozwala atakującym posiadającym globalne uprawnienie Item/Configure (bez uprawnień Item/Configure na żadnym konkretnym zadaniu) na enumerację identyfikatorów poświadczeń o zasięgu systemowym przechowywanych w Jenkins i łączenie się z Google Cloud Platform przy użyciu identyfikatorów poświadczeń wskazanych przez atakującego pozyskanych innymi metodami w celu uzyskania informacji o istniejących projektach. Poprawka została wportowana do wersji 4.3.17.1.

Pokaż oryginał (EN)

Incorrect permission checks in Jenkins Google Compute Engine Plugin 4.550.vb_327fca_3db_11 and earlier allow attackers with global Item/Configure permission (while lacking Item/Configure permission on any particular job) to enumerate system-scoped credentials IDs of credentials stored in Jenkins and to connect to Google Cloud Platform using attacker-specified credentials IDs obtained through another method, to obtain information about existing projects. This fix has been backported to 4.3.17.1.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N
  • Jenkins Google Compute Engine

    APP
    Jenkins
    < 4.3.17.1
🟢
PATCH DOSTĘPNY
Aktualizacja od producenta gotowa. Wdrożenie w ramach standardowego cyklu.
Tagi
CI/CD
CWE
Referencje

Powiązane podatności

CVE-2023-49673HIGH8.8ten sam produkt

A cross-site request forgery (CSRF) vulnerability in Jenkins NeuVector Vulnerability Scanner Plugin 1.22 and e...

CVE-2019-16548HIGH8.8ten sam produkt

A cross-site request forgery vulnerability in Jenkins Google Compute Engine Plugin 4.1.1 and earlier in Comput...

CVE-2022-29052MEDIUM4.3ten sam produkt

Jenkins Google Compute Engine Plugin 4.3.8 and earlier stores private keys unencrypted in cloud agent config.x...

CVE-2019-16546MEDIUM5.9ten sam produkt

Jenkins Google Compute Engine Plugin 4.1.1 and earlier does not verify SSH host keys when connecting agents cr...

CVE-2019-16547MEDIUM4.3ten sam produkt

Missing permission checks in various API endpoints in Jenkins Google Compute Engine Plugin 4.1.1 and earlier a...