« Volver al listado

CVE-2023-49653

Estado: ModificadaMedia (6.5)—

Jenkins Jira Plugin 3.11 and earlier does not set the appropriate context for credentials lookup, allowing attackers with Item/Configure permission to access and capture credentials they are not entitled to.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2023-49653",
  "cveTags": [],
  "metrics": {
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 6.5,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "jenkinsci-cert@googlegroups.com",
      "affectedData": [
        {
          "vendor": "Jenkins Project",
          "product": "Jenkins Jira Plugin",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "versionType": "maven",
              "lessThanOrEqual": "3.11"
            }
          ],
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2023-11-29T14:15:07.527",
  "references": [
    {
      "url": "http://www.openwall.com/lists/oss-security/2023/11/29/1",
      "tags": [
        "Mailing List",
        "Third Party Advisory"
      ],
      "source": "jenkinsci-cert@googlegroups.com"
    },
    {
      "url": "https://www.jenkins.io/security/advisory/2023-11-29/#SECURITY-3225",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "jenkinsci-cert@googlegroups.com"
    },
    {
      "url": "http://www.openwall.com/lists/oss-security/2023/11/29/1",
      "tags": [
        "Mailing List",
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://www.jenkins.io/security/advisory/2023-11-29/#SECURITY-3225",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-522"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Jenkins Jira Plugin 3.11 and earlier does not set the appropriate context for credentials lookup, allowing attackers with Item/Configure permission to access and capture credentials they are not entitled to."
    },
    {
      "lang": "es",
      "value": "Jenkins Jira Plugin 3.11 y versiones anteriores no establecen el contexto apropiado para la búsqueda de credenciales, lo que permite a los atacantes con permiso Elemento/Configurar acceder y capturar credenciales a las que no tienen derecho."
    }
  ],
  "lastModified": "2026-06-17T06:36:16.617",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:jenkins:jira:*:*:*:*:*:jenkins:*:*",
              "vulnerable": true,
              "matchCriteriaId": "9C76F400-F7A8-4BE9-AB72-1BEB2FEDD52E",
              "versionEndIncluding": "3.11"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "jenkinsci-cert@googlegroups.com"
}