Total vulnerabilities in the database
Jenkins Jira Plugin 3.11 and earlier does not set the appropriate context for credentials lookup, allowing attackers with Item/Configure permission to access and capture credentials they are not entitled to.
Software | From | Fixed in |
---|---|---|
![]() |
- | 3.12 |
jenkins / jira | - | 3.11.x |