Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-2008 | Incorrect permission checks in Jenkins Qualys Web App Scanning Connector Plugin 2.0.10 and earlier allow attackers with global Item/Configure permission to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins. |
Github GHSA |
GHSA-8wgf-3mrj-73x7 | Incorrect permission checks in Qualys Web App Scanning Connector Plugin allow capturing credentials |
Wed, 23 Oct 2024 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: jenkins
Published:
Updated: 2024-10-23T14:46:37.651Z
Reserved: 2023-07-25T11:16:13.336Z
Link: CVE-2023-39154
Updated: 2024-08-02T18:02:06.202Z
Status : Modified
Published: 2023-07-26T14:15:10.647
Modified: 2024-11-21T08:14:48.857
Link: CVE-2023-39154
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA