Description
A missing permission check in Jenkins OctoPerf Load Testing Plugin Plugin 4.5.2 and earlier allows attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.
Remediation
References
https://www.jenkins.io/security/advisory/2023-03-21/#SECURITY-3067%20(3)
Related Vulnerabilities
CVE-2019-17570 Vulnerability in maven package org.apache.xmlrpc:xmlrpc
CVE-2017-15686 Vulnerability in maven package org.craftercms:crafter-studio
CVE-2022-45935 Vulnerability in maven package org.apache.james:apache-james-mailbox-store
CVE-2009-0217 Vulnerability in maven package org.apache.santuario:xmlsec
CVE-2020-24922 Vulnerability in maven package com.xuxueli:xxl-job-admin