{"id":"GHSA-rv6g-3v76-cvf9","summary":"Jenkins Azure VM Agents Plugin missing permission checks","details":"Jenkins Azure VM Agents Plugin 852.v8d35f0960a_43 and earlier does not perform permission checks in several HTTP endpoints.\n\nThis allows attackers with Overall/Read permission to connect to an attacker-specified Azure Cloud server using attacker-specified credentials IDs obtained through another method.\n\nAdditionally, these HTTP endpoints do not require POST requests, resulting in a cross-site request forgery (CSRF) vulnerability.\n\nAzure VM Agents Plugin 853.v4a_1a_dd947520 requires POST requests and the appropriate permissions for the affected HTTP endpoints.","aliases":["CVE-2023-32990"],"modified":"2023-11-08T05:21:35.371507Z","published":"2023-05-16T18:30:16Z","database_specific":{"cwe_ids":["CWE-732"],"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2023-05-17T03:30:10Z","nvd_published_at":"2023-05-16T17:15:11Z"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-32990"},{"type":"WEB","url":"https://www.jenkins.io/security/advisory/2023-05-16/#SECURITY-2855%20(2)"}],"affected":[{"package":{"name":"org.jenkins-ci.plugins:azure-vm-agents","ecosystem":"Maven","purl":"pkg:maven/org.jenkins-ci.plugins/azure-vm-agents"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"853.v4a"}]}],"versions":["0.4.0","0.4.1","0.4.2","0.4.3","0.4.4","0.4.5","0.4.5.1","0.4.6","0.4.7","0.4.7.1","0.4.8","0.5.0","0.6.0","0.6.1","0.6.2","0.7.0","0.7.1","0.7.2","0.7.2.1","0.7.3","0.7.4","0.7.5","0.8.0","0.8.1","0.9.0","1.0.0","1.0.1","1.1.0","1.1.1","1.2.0","1.2.1","1.2.2","1.3.0","1.4.0","1.4.1","1.5.0","1.5.1","1.5.2","1.5.3","759.v1c1f79435487","760.ve25700ee68cc","761.v8d93e0672563","763.vedbebdfd1222","764.vf22cf908cb69","765.vbb9943c5070c","766.vbdb82c53e70a","768.vb8b0d31eef4f","774.v0cee503baa25","775.v0bbd3d0d016a","777.v276476e1344c","778.va3924310a4eb","779.v5ea1414ec40f","780.v50d067d02f76","781.v5877a4d99d28","782.vb41dc00d85b1","783.v58077630847d","789.va0c40e4d0070","793.vbb935f9be778","794.v8a62ee91dc70","795.vd5903dae1139","797.v31f530348574","799.va4c741108611","801.v37f3eab68cf0","802.vbac7a8a5d5e2","803.vef83d334600f","804.ve77d45cc9464","805.v424cc2981d7a","806.vae775cde5efa","808.v9d1999587120","810.v0a97a847315a","813.v8ae017133e51","815.vf2f07da070ee","816.v27bbb474b2b2","822.v3a18fc3d2de1","824.v31b_9c29f67fd","825.v470cb_9e7361a_","842.v9fedb_4cc1b_e9","845.v35ee7c5570db_","846.v5a_f7e3dce959","851.v16b_dcb_e85c85","852.v8d35f0960a_43"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/05/GHSA-rv6g-3v76-cvf9/GHSA-rv6g-3v76-cvf9.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N"}]}