6.5
CVSSv3

CVE-2023-46651

Published: 25/10/2023 Updated: 01/11/2023
CVSS v3 Base Score: 6.5 | Impact Score: 3.6 | Exploitability Score: 2.8
VMScore: 0

Vulnerability Summary

Jenkins Warnings Plugin 10.5.0 and previous versions does not set the appropriate context for credentials lookup, allowing attackers with Item/Configure permission to access and capture credentials they are not entitled to. This fix has been backported to 10.4.1.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

jenkins warnings