{"id":"GHSA-px2r-cmr2-phw7","summary":"Missing Authorization in Jenkins Azure Credentials Plugin","details":"A missing permission check in Jenkins Azure Credentials Plugin 253.v887e0f9e898b and earlier allows attackers with Overall/Read permission to connect to an attacker-specified web server.","aliases":["CVE-2023-25768"],"modified":"2024-02-16T08:25:28.639712Z","published":"2023-02-15T15:30:40Z","database_specific":{"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2023-02-15T18:32:57Z","nvd_published_at":"2023-02-15T14:15:00Z","cwe_ids":["CWE-862","CWE-863"]},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-25768"},{"type":"WEB","url":"https://github.com/jenkinsci/azure-credentials-plugin/commit/64da8176c83a41bb83d3ad759628c9bd275b42f5"},{"type":"PACKAGE","url":"https://github.com/jenkinsci/azure-credentials-plugin"},{"type":"WEB","url":"https://www.jenkins.io/security/advisory/2023-02-15/#SECURITY-1756"},{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2023/02/15/4"}],"affected":[{"package":{"name":"org.jenkins-ci.plugins:azure-credentials","ecosystem":"Maven","purl":"pkg:maven/org.jenkins-ci.plugins/azure-credentials"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"254.v64da_8176c83a"}]}],"versions":["1.0","1.1","1.2","1.3","1.3.1","1.4.0","1.5.0","1.6.0","1.6.1","177.v816b81058012","180.vd0decee98185","181.v00b0d97d2686","182.v3ccd4a755864","189.v479ef8f0344f","190.v059127ae17bb","196.va1e78c9989ea","197.v2f5ab5b82264","198.vf9c2fdfde55c","2.0.0","2.0.1","2.0.2","216.ve0b_4a_485ffc2","242.vb_f9c4fa_6b_2b_6","252.vd40e833b_3206","253.v887e0f9e898b","3.0.0","3.0.1","4.0.0","4.0.1","4.0.2","4.0.3","4.0.4","4.0.5","4.0.6"],"database_specific":{"last_known_affected_version_range":"\u003c= 253.v887e0f9e898b","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/02/GHSA-px2r-cmr2-phw7/GHSA-px2r-cmr2-phw7.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N"}]}