Description
Missing permission checks in Jenkins Ansible Plugin 1.0 and earlier allow attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.
Remediation
References
https://www.jenkins.io/security/advisory/2020-11-04/#SECURITY-1943
Related Vulnerabilities
CVE-2017-17837 Vulnerability in maven package org.apache.deltaspike.modules:jsf-module-project
CVE-2014-0003 Vulnerability in maven package org.apache.camel:camel-core
CVE-2017-4974 Vulnerability in maven package org.cloudfoundry.identity:cloudfoundry-identity-server
CVE-2020-17518 Vulnerability in maven package org.apache.flink:flink-runtime_2.12
CVE-2021-21691 Vulnerability in maven package org.jenkins-ci.main:jenkins-core