MEDIUM4.3
GHSA-wwww-xvm2-62w7
Jenkins Delphix Plugin vulnerable to exposure of system-scoped credentials
Quick fix
GHSA-wwww-xvm2-62w7 — org.jenkins-ci.plugins:delphix: upgrade to the fixed version with the command below.
# pom.xml: bump <version>3.0.3</version> for org.jenkins-ci.plugins:delphixDetails
Jenkins Delphix Plugin 3.0.2 and earlier does not set the appropriate context for credentials lookup, allowing the use of System-scoped credentials otherwise reserved for the global configuration.
This allows attackers with Overall/Read permission to access and capture credentials they are not entitled to.
Delphix Plugin 3.0.3 defines the appropriate context for credentials lookup.
Are you affected?
Enter the version of the package you're using.
Affected packages
Maven/org.jenkins-ci.plugins:delphix
Introduced in:
0Fixed in: 3.0.3Fix
# pom.xml: bump <version>3.0.3</version> for org.jenkins-ci.plugins:delphixReferences
- https://nvd.nist.gov/vuln/detail/CVE-2023-40345[ADVISORY]
- https://support.delphix.com/Support_Policies_and_Technical_Bulletins/Technical_Bulletins/TB111_Delphix_Plugin_for_Jenkins_Vulnerable_to_Credential_Enumeration_and_Capture[WEB]
- https://www.jenkins.io/security/advisory/2023-08-16/#SECURITY-3214%20(2)[WEB]
- http://www.openwall.com/lists/oss-security/2023/08/16/3[WEB]