Vulnerabilities > CVE-2023-35149 - Missing Authorization vulnerability in Jenkins Digital.Ai APP Management Publisher

047910
CVSS 6.5 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
LOW
Confidentiality impact
HIGH
Integrity impact
NONE
Availability impact
NONE
network
low complexity
jenkins
CWE-862

Summary

A missing permission check in Jenkins Digital.ai App Management Publisher Plugin 2.6 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL, capturing credentials stored in Jenkins.

Common Weakness Enumeration (CWE)