Potential leak of credentials in Micro Focus Dimensions CM Jenkins Plugin
Low severity
GitHub Reviewed
Published
Jul 19, 2023
to the GitHub Advisory Database
•
Updated Jan 30, 2024
Package
Affected versions
>= 0.8.17, <= 0.9.3
Patched versions
0.9.3.1
Description
Published by the National Vulnerability Database
Jul 19, 2023
Published to the GitHub Advisory Database
Jul 19, 2023
Reviewed
Jan 30, 2024
Last updated
Jan 30, 2024
A potential vulnerability has been identified in the Micro Focus Dimensions CM Plugin for Jenkins. The vulnerability could be exploited to retrieve a login certificate if an authenticated user is duped into using an attacker-controlled Dimensions CM server. This vulnerability only applies when the Jenkins plugin is configured to use login certificate credentials.
References