Jenkins Delphix Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with access to the master file system.
Jenkins Delphix Plugin 3.0.2 and earlier does not set the appropriate context for credentials lookup, allowing attackers with Overall/Read permission to access and capture credentials they are not entitled to.
In Jenkins Delphix Plugin 3.0.1, a global option for administrators to enable or disable SSL/TLS certificate validation for Data Control Tower (DCT) connections is disabled by default.
A missing permission check in Jenkins Delphix Plugin 3.0.2 and earlier allows attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.
In Jenkins Delphix Plugin 3.0.1 through 3.1.0 (both inclusive) a global option for administrators to enable or disable SSL/TLS certificate validation for Data Control Tower (DCT) connections fails to take effect until Jenkins is restarted when switching from disabled validation to enabled validation.
Published 2024-03-06 · Analyzed
4.2EPSS 0.003
Demo
ThreatFusionAI™ Product Walkthrough
The fastest way to see what ThreatFusionAI does is to run a search. Paste any hash, IP, domain or CVE and you'll get the full report, the connected indicators and the actor attribution in one pass.
What you'll see
• Verdicts from multiple antivirus engines
• The connected IOC graph you can click through
• Ranked threat actors based on ATT&CK overlap
Next step
Start with a free search, no card needed. Check the plans if you need more volume.
ThreatFusionAI AssistantAI help & guidance
AI assistant — can make mistakes. Verify important results.