Description
A missing permission check in Jenkins loader.io Plugin 1.0.1 and earlier allows attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.
Remediation
References
https://www.jenkins.io/security/advisory/2022-11-15/#SECURITY-2857
http://www.openwall.com/lists/oss-security/2022/11/15/4
Related Vulnerabilities
CVE-2022-24847 Vulnerability in maven package org.geoserver.web:gs-web-sec-jdbc
CVE-2018-1051 Vulnerability in maven package org.jboss.resteasy:resteasy-yaml-provider
CVE-2016-0779 Vulnerability in maven package org.apache.tomee:openejb-core
CVE-2023-48631 Vulnerability in npm package @adobe/css-tools
CVE-2022-43396 Vulnerability in maven package org.apache.kylin:kylin-spark-engine