Description
Jenkins Compuware Topaz for Total Test Plugin 2.4.8 and earlier does not perform permission checks in several HTTP endpoints, allowing attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.
Remediation
References
http://www.openwall.com/lists/oss-security/2022/10/19/3
https://www.jenkins.io/security/advisory/2022-10-19/#SECURITY-2623
Related Vulnerabilities
CVE-2019-12384 Vulnerability in maven package com.fasterxml.jackson.core:jackson-databind
CVE-2020-2211 Vulnerability in maven package com.elasticbox.jenkins-ci.plugins:kubernetes-ci
CVE-2022-29078 Vulnerability in npm package ejs
CVE-2022-46907 Vulnerability in maven package org.apache.jspwiki:jspwiki-main