Source |
CVE Liste |
Identifiant |
4670392 |
Date de publication |
2022-05-17 15:15:09 (vue: 2022-05-17 17:06:37) |
Titre |
CVE-2022-30952 |
Texte |
Jenkins Pipeline SCM API for Blue Ocean Plugin 1.25.3 and earlier allows attackers with Job/Configure permission to access credentials with attacker-specified IDs stored in the private per-user credentials stores of any attacker-specified user in Jenkins. |
Notes |
★★
|
Envoyé |
Oui |
Condensat |
2022 30952 access allows any api attacker attackers blue credentials cve earlier ids jenkins job/configure ocean per permission pipeline plugin private scm specified stored stores user |
Tags |
|
Stories |
APT 32
|
Move |
|