A missing permission check in Jenkins Azure Key Vault Plugin 2.0 and earlier allows attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.
Affected Software
| Name | Vendor | Start Version | End Version |
|---|
| Azure_key_vault | Jenkins | * | 2.0 (including) |
References