CVE-2023-32990
16.05.2023, 17:15
A missing permission check in Jenkins Azure VM Agents Plugin 852.v8d35f0960a_43 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified Azure Cloud server using attacker-specified credentials IDs obtained through another method.Enginsight
Vendor | Product | Version |
---|---|---|
jenkins | azure_vm_agents | 𝑥 ≤ 852.v8d35f0960a_43 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration