CVE-2023-40347
Last modified
CVE-2023-40347 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. Jenkins Maven Artifact ChoiceListProvider (Nexus) Plugin 1.14 and earlier does not set the appropriate context for credentials lookup, allowing attackers with Item/Configure permission to access and capture credentials they are not entitled to.. EPSS estimates a 0.56% chance of exploitation in the next 30 days.
Description
Jenkins Maven Artifact ChoiceListProvider (Nexus) Plugin 1.14 and earlier does not set the appropriate context for credentials lookup, allowing attackers with Item/Configure permission to access and capture credentials they are not entitled to.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Jenkins | Maven Artifact Choicelistprovider \(Nexus\) | <= 1.14 |
References
- http://www.openwall.com/lists/oss-security/2023/08/16/3Mailing List, Third Party Advisory
- http://www.openwall.com/lists/oss-security/2023/08/16/3Mailing List, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2023-40347?
How severe is CVE-2023-40347?
How do I fix CVE-2023-40347?
Are you affected by CVE-2023-40347?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
