Jenkins Config File Provider Plugin 3.7.0 and earlier does not correctly perform permission checks in several HTTP endpoints, allowing attackers with global Job/Configure permission to enumerate system-scoped credentials IDs of credentials stored in Jenkins.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Config_file_provider | Jenkins | * | 3.7.0 (including) |
Red Hat Migration Toolkit for Containers 1.4 | RedHat | rhmtc/openshift-migration-controller-rhel8:v1.4.6-4 | * |
Red Hat Migration Toolkit for Containers 1.4 | RedHat | rhmtc/openshift-migration-log-reader-rhel8:v1.4.6-4 | * |
Red Hat Migration Toolkit for Containers 1.4 | RedHat | rhmtc/openshift-migration-must-gather-rhel8:v1.4.6-4 | * |
Red Hat Migration Toolkit for Containers 1.4 | RedHat | rhmtc/openshift-migration-operator-bundle:v1.4.6-5 | * |
Red Hat Migration Toolkit for Containers 1.4 | RedHat | rhmtc/openshift-migration-registry-rhel8:v1.4.6-4 | * |
Red Hat Migration Toolkit for Containers 1.4 | RedHat | rhmtc/openshift-migration-rsync-transfer-rhel8:v1.4.6-4 | * |
Red Hat Migration Toolkit for Containers 1.4 | RedHat | rhmtc/openshift-migration-ui-rhel8:v1.4.6-4 | * |
Red Hat Migration Toolkit for Containers 1.4 | RedHat | rhmtc/openshift-migration-velero-plugin-for-aws-rhel8:v1.4.6-4 | * |
Red Hat Migration Toolkit for Containers 1.4 | RedHat | rhmtc/openshift-migration-velero-plugin-for-gcp-rhel8:v1.4.6-3 | * |
Red Hat Migration Toolkit for Containers 1.4 | RedHat | rhmtc/openshift-migration-velero-plugin-for-microsoft-azure-rhel8:v1.4.6-4 | * |
Red Hat Migration Toolkit for Containers 1.4 | RedHat | rhmtc/openshift-migration-velero-restic-restore-helper-rhel8:v1.4.6-5 | * |
Red Hat Migration Toolkit for Containers 1.4 | RedHat | rhmtc/openshift-migration-velero-rhel8:v1.4.6-5 | * |
Red Hat Migration Toolkit for Containers 1.4 | RedHat | rhmtc/openshift-velero-plugin-rhel8:v1.4.6-4 | * |
Red Hat OpenShift Container Platform 3.11 | RedHat | jenkins-2-plugins-0:3.11.1624366838-1.el7 | * |
Red Hat OpenShift Container Platform 4.5 | RedHat | jenkins-2-plugins-0:4.5.1623326336-1.el7 | * |
Red Hat OpenShift Container Platform 4.6 | RedHat | jenkins-2-plugins-0:4.6.1623162648-1.el8 | * |
Red Hat OpenShift Container Platform 4.7 | RedHat | cri-o-0:1.20.2-12.rhaos4.7.git9f7be76.el8 | * |
Red Hat OpenShift Container Platform 4.7 | RedHat | cri-tools-0:1.20.0-3.el7 | * |
Red Hat OpenShift Container Platform 4.7 | RedHat | jenkins-2-plugins-0:4.7.1621361158-1.el8 | * |
Red Hat OpenShift Container Platform 4.7 | RedHat | redhat-release-coreos-0:47.83-2.el8 | * |