Total vulnerabilities in the database
An improper authorization vulnerability exists in Jenkins Jira Plugin 3.0.1 and earlier in JiraSite.java that allows attackers with Overall/Read access to have Jenkins connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.
Software | From | Fixed in |
---|---|---|
jenkins / jira | - | 3.0.1.x |
![]() |
- | 3.0.2 |