← Zuruck zu CVEs
CVE-2023-30527
MEDIUM4.3
Beschreibung
Jenkins WSO2 Oauth Plugin 1.0 and earlier stores the WSO2 Oauth client secret unencrypted in the global config.xml file on the Jenkins controller where it can be viewed by users with access to the Jenkins controller file system.
CVE Details
CVSS v3.1 Bewertung4.3
SchweregradMEDIUM
CVSS VektorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
AngriffsvektorNETWORK
KomplexitatLOW
Erforderliche PrivilegienLOW
BenutzerinteraktionNONE
Veroffentlicht4/12/2023
Zuletzt geandert2/7/2025
Quellenvd
Honeypot-Sichtungen0
Betroffene Produkte
jenkins:wso2_oauth
Schwachen (CWE)
CWE-312CWE-312
Referenzen
http://www.openwall.com/lists/oss-security/2023/04/13/3(jenkinsci-cert@googlegroups.com)
https://www.jenkins.io/security/advisory/2023-04-12/#SECURITY-2992(jenkinsci-cert@googlegroups.com)
http://www.openwall.com/lists/oss-security/2023/04/13/3(af854a3a-2127-422b-91ae-364da2661108)
https://www.jenkins.io/security/advisory/2023-04-12/#SECURITY-2992(af854a3a-2127-422b-91ae-364da2661108)
IOC Korrelationen
Keine Korrelationen erfasst
This product uses data from the NVD API but is not endorsed or certified by the NVD.