Description
Missing permission checks in Jenkins Ansible Plugin 1.0 and earlier allow attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.
Remediation
References
https://www.jenkins.io/security/advisory/2020-11-04/#SECURITY-1943
Related Vulnerabilities
CVE-2023-22849 Vulnerability in maven package org.apache.sling:org.apache.sling.cms.ui
CVE-2020-2109 Vulnerability in maven package org.jenkins-ci.plugins.workflow:workflow-cps
CVE-2017-15703 Vulnerability in maven package org.apache.nifi:nifi-framework-core
CVE-2023-46674 Vulnerability in maven package org.elasticsearch:elasticsearch-hadoop
CVE-2019-1003036 Vulnerability in maven package org.jenkins-ci.plugins:azure-vm-agents