{"id":"GHSA-px39-5h8c-j3c8","summary":"Exposure of system-scoped credentials in Jenkins Dimensions Plugin","details":"Dimensions Plugin 0.9.3 and earlier does not set the appropriate context for credentials lookup, allowing the use of System-scoped credentials otherwise reserved for the global configuration.\n\nThis allows attackers with Item/Configure permission to access and capture credentials they are not entitled to.\n\nDimensions Plugin 0.9.3.1 defines the appropriate context for credentials lookup.","aliases":["CVE-2023-32262"],"modified":"2024-12-05T05:31:37.470136Z","published":"2023-07-19T18:30:56Z","database_specific":{"cwe_ids":[],"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2024-01-30T23:03:23Z","nvd_published_at":"2023-07-19T16:15:09Z"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-32262"},{"type":"WEB","url":"https://plugins.jenkins.io/dimensionsscm"},{"type":"WEB","url":"https://portal.microfocus.com/s/article/KM000019298"},{"type":"WEB","url":"https://www.jenkins.io/security/advisory/2023-06-14/#SECURITY-3143"}],"affected":[{"package":{"name":"org.jenkins-ci.plugins:dimensionsscm","ecosystem":"Maven","purl":"pkg:maven/org.jenkins-ci.plugins/dimensionsscm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.9.3.1"}]}],"versions":["0.7.11","0.8.1","0.8.10","0.8.11","0.8.12","0.8.13","0.8.14","0.8.15","0.8.16","0.8.17","0.8.18","0.8.19","0.8.3.1","0.8.5","0.8.6","0.8.8","0.8.9","0.9.0","0.9.1","0.9.2","0.9.3"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/07/GHSA-px39-5h8c-j3c8/GHSA-px39-5h8c-j3c8.json","last_known_affected_version_range":"\u003c= 0.9.3"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"}]}