CVE-2023-39154

CVSS 3.1 Score 6.5 of 10 (medium)

Details

Published Jul 26, 2023
Updated: Jul 31, 2023
CWE ID 863

Summary

CVE-2023-39154 is a vulnerability affecting the Jenkins Qualys Web App Scanning Connector Plugin version 2.0.10 and earlier. This issue stems from flawed permission checks, enabling users with global Item/Configure permissions to connect to URLs of an attacker's choice using arbitrary credentials. These credentials can be obtained through external means and subsequently misused to gain unauthorized access to Jenkins-stored credentials.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share