{"id":"CVE-2023-49652","details":"Incorrect permission checks in Jenkins Google Compute Engine Plugin 4.550.vb_327fca_3db_11 and earlier allow attackers with global Item/Configure permission (while lacking Item/Configure permission on any particular job) to enumerate system-scoped credentials IDs of credentials stored in Jenkins and to connect to Google Cloud Platform using attacker-specified credentials IDs obtained through another method, to obtain information about existing projects. This fix has been backported to 4.3.17.1.","aliases":["GHSA-pgpj-83g3-mfr2"],"modified":"2026-08-18T13:28:13.495892Z","published":"2023-11-29T14:15:07.460Z","references":[{"type":"ADVISORY","url":"http://www.openwall.com/lists/oss-security/2023/11/29/1"},{"type":"ADVISORY","url":"https://www.jenkins.io/security/advisory/2023-11-29/#SECURITY-2835"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/jenkinsci/google-compute-engine-plugin","events":[{"introduced":"0"},{"fixed":"67052215b9d2c268452449c738c8cad72dc3f21f"}],"database_specific":{"cpe":"cpe:2.3:a:jenkins:google_compute_engine:*:*:*:*:*:jenkins:*:*","extracted_events":[{"introduced":"0"},{"fixed":"4.3.17.1"}],"source":"CPE_RANGE"}}],"versions":["google-compute-engine-4.3.17","google-compute-engine-4.3.16","google-compute-engine-4.3.15","google-compute-engine-4.3.14","google-compute-engine-4.3.13","google-compute-engine-4.3.12","google-compute-engine-4.3.11","google-compute-engine-4.3.10","google-compute-engine-4.3.9","google-compute-engine-4.3.8","google-compute-engine-4.3.7","google-compute-engine-4.3.6","google-compute-engine-4.3.5","google-compute-engine-4.3.4","google-compute-engine-4.3.3","google-compute-engine-4.3.2","google-compute-engine-4.3.1","google-compute-engine-3.3.0","google-compute-engine-3.1.1","google-compute-engine-3.1.0","google-compute-engine-3.0.0","google-compute-engine-2.0.0","google-compute-engine-1.0.10","google-compute-engine-1.0.9","google-compute-engine-1.0.8","google-compute-engine-1.0.7","google-compute-engine-1.0.6","google-compute-engine-1.0.5","google-compute-engine-1.0.4","google-compute-engine-1.0.3","google-compute-engine-1.0.2","google-compute-engine-1.0.1","google-compute-engine-1.0.0","google-compute-engine-1.0-beta-2","google-compute-engine-1.0-beta-1","1.0.0-alpha.01"],"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2023-49652.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N"}]}