Jenkins Xray - Test Management for Jira Plugin 2.4.0 and previous versions does not perform a permission check in an HTTP endpoint, allowing with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
jenkins xray - test management for jira |