Description
Incorrect permission checks in Jenkins Qualys Web App Scanning Connector Plugin 2.0.10 and earlier allow attackers with global Item/Configure permission to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.
Product status
Any version
References
www.jenkins.io/security/advisory/2023-07-26/ (Jenkins Security Advisory 2023-07-26)
www.openwall.com/lists/oss-security/2023/07/26/2
www.jenkins.io/security/advisory/2023-07-26/ (Jenkins Security Advisory 2023-07-26)
www.openwall.com/lists/oss-security/2023/07/26/2