GHSA-8hc6-w44m-wfxf

Suggest an improvement
Source
https://github.com/advisories/GHSA-8hc6-w44m-wfxf
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/07/GHSA-8hc6-w44m-wfxf/GHSA-8hc6-w44m-wfxf.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-8hc6-w44m-wfxf
Aliases
Published
2023-07-19T18:30:56Z
Modified
2024-12-05T05:39:08.513071Z
Severity
  • 2.6 (Low) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:N/A:N CVSS Calculator
Summary
Potential leak of credentials in Micro Focus Dimensions CM Jenkins Plugin
Details

A potential vulnerability has been identified in the Micro Focus Dimensions CM Plugin for Jenkins. The vulnerability could be exploited to retrieve a login certificate if an authenticated user is duped into using an attacker-controlled Dimensions CM server. This vulnerability only applies when the Jenkins plugin is configured to use login certificate credentials.

Database specific
{
    "nvd_published_at": "2023-07-19T16:15:09Z",
    "cwe_ids": [],
    "severity": "LOW",
    "github_reviewed": true,
    "github_reviewed_at": "2024-01-30T23:04:11Z"
}
References

Affected packages

Maven / org.jenkins-ci.plugins:dimensionsscm

Package

Name
org.jenkins-ci.plugins:dimensionsscm
View open source insights on deps.dev
Purl
pkg:maven/org.jenkins-ci.plugins/dimensionsscm

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0.8.17
Fixed
0.9.3.1

Affected versions

0.*

0.8.17
0.8.18
0.8.19
0.9.0
0.9.1
0.9.2
0.9.3

Database specific

{
    "last_known_affected_version_range": "<= 0.9.3"
}