Missing permission checks in Jenkins Ansible Plugin 1.0 and earlier allow attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.
Affected Software
Name |
Vendor |
Start Version |
End Version |
Ansible |
Jenkins |
* |
1.0 (including) |
References