VDB
Sign up
MEDIUM4.3

GHSA-wwww-xvm2-62w7

Jenkins Delphix Plugin vulnerable to exposure of system-scoped credentials

Quick fix

GHSA-wwww-xvm2-62w7 — org.jenkins-ci.plugins:delphix: upgrade to the fixed version with the command below.

# pom.xml: bump <version>3.0.3</version> for org.jenkins-ci.plugins:delphix

Details

Jenkins Delphix Plugin 3.0.2 and earlier does not set the appropriate context for credentials lookup, allowing the use of System-scoped credentials otherwise reserved for the global configuration.

This allows attackers with Overall/Read permission to access and capture credentials they are not entitled to.

Delphix Plugin 3.0.3 defines the appropriate context for credentials lookup.

Are you affected?

Enter the version of the package you're using.

Affected packages

Maven/org.jenkins-ci.plugins:delphix
Introduced in: 0Fixed in: 3.0.3
Fix# pom.xml: bump <version>3.0.3</version> for org.jenkins-ci.plugins:delphix

References