QID 983817
QID 983817: Java (maven) Security Update for org.jenkins-ci.plugins:xray-connector (GHSA-5557-j87h-cvf4)
Jenkins Xray - Test Management for Jira Plugin 2.4.0 and earlier does not perform a permission check in an HTTP endpoint, allowing with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-5557-j87h-cvf4 for updates pertaining to this vulnerability.
Vendor References
- GHSA-5557-j87h-cvf4 -
github.com/advisories/GHSA-5557-j87h-cvf4
CVEs related to QID 983817
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-5557-j87h-cvf4 | org.jenkins-ci.plugins:xray-connector |
|