CVE-2023-40347
Description
Jenkins Maven Artifact ChoiceListProvider (Nexus) Plugin 1.14 and earlier does not set the appropriate context for credentials lookup, allowing attackers with Item/Configure permission to access and capture credentials they are not entitled to.
References
Vendor Advisory
Mailing ListThird Party Advisory
CvssV3 impact
Could not find any metrics
CvssV2 impact
Could not find any metrics