CVE Published: 27/07/2022 |
CVE Updated: 03/08/2024 |
CVE Year: 2022 Source: jenkins |
Vendor: Jenkins project |
Product: Jenkins Compuware Source Code Download for Endevor, PDS, and ISPW Plugin Status : PUBLISHED
CVE-2022-36896 Description
A missing permission check in Jenkins Compuware Source Code Download for Endevor, PDS, and ISPW Plugin 2.0.12 and earlier allows attackers with Overall/Read permission to enumerate hosts and ports of Compuware configurations and credentials IDs of credentials stored in Jenkins.