A potential vulnerability has been identified in the Micro Focus Dimensions CM Plugin for Jenkins. The vulnerability could be exploited to retrieve a login certificate if an authenticated user is duped into using an attacker-controlled Dimensions CM server. This vulnerability only applies when the Jenkins plugin is configured to use login certificate credentials.
{
"github_reviewed": true,
"severity": "LOW",
"github_reviewed_at": "2024-01-30T23:04:11Z",
"nvd_published_at": "2023-07-19T16:15:09Z",
"cwe_ids": []
}