CVE Published: 26/07/2023 |
CVE Updated: 23/10/2024 |
CVE Year: 2023 Source: jenkins |
Vendor: Jenkins Project |
Product: Jenkins Qualys Web App Scanning Connector Plugin Status : PUBLISHED
CVE-2023-39154 Description
Incorrect permission checks in Jenkins Qualys Web App Scanning Connector Plugin 2.0.10 and earlier allow attackers with global Item/Configure permission to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.