Missing permission checks in Synopsys Jenkins Coverity Plugin 3.0.2 and...
Vulnerability Description
Missing permission checks in Synopsys Jenkins Coverity Plugin 3.0.2 and earlier allow attackers with Overall/Read permission to connect to an attacker-specified HTTP server using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2023-23848
Credits & Attribution
No credits recorded in the NVD database.
References
More from Synopsys
View All →Affected Vendor
Synopsys
View all reports →