An incorrect permission check in Qualys Container...
Moderate severity
Unreviewed
Published
Sep 8, 2023
to the GitHub Advisory Database
•
Updated Apr 4, 2024
Description
Published by the National Vulnerability Database
Sep 8, 2023
Published to the GitHub Advisory Database
Sep 8, 2023
Last updated
Apr 4, 2024
An incorrect permission check in Qualys Container Scanning Connector Plugin 1.6.2.6 and earlier allows attackers with global Item/Configure permission (while lacking Item/Configure permission on any particular job) to enumerate credentials IDs of credentials stored in Jenkins and to connect to an attacker-specified URL using attacker-specified credentials IDs, capturing credentials stored in Jenkins.
References