CVE-2023-32990

Source
https://nvd.nist.gov/vuln/detail/CVE-2023-32990
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2023-32990.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2023-32990
Aliases
Published
2023-05-16T17:15:11Z
Modified
2024-10-12T09:25:35.193740Z
Severity
  • 6.5 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N CVSS Calculator
Summary
[none]
Details

A missing permission check in Jenkins Azure VM Agents Plugin 852.v8d35f0960a_43 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified Azure Cloud server using attacker-specified credentials IDs obtained through another method.

References

Affected packages

Git / github.com/jenkinsci/azure-vm-agents-plugin

Affected ranges

Type
GIT
Repo
https://github.com/jenkinsci/azure-vm-agents-plugin
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected

Affected versions

759.*

759.v1c1f79435487

760.*

760.ve25700ee68cc

761.*

761.v8d93e0672563

763.*

763.vedbebdfd1222

764.*

764.vf22cf908cb69

765.*

765.vbb9943c5070c

766.*

766.vbdb82c53e70a

768.*

768.vb8b0d31eef4f

774.*

774.v0cee503baa25

775.*

775.v0bbd3d0d016a

777.*

777.v276476e1344c

778.*

778.va3924310a4eb

779.*

779.v5ea1414ec40f

780.*

780.v50d067d02f76

781.*

781.v5877a4d99d28

782.*

782.vb41dc00d85b1

783.*

783.v58077630847d

789.*

789.va0c40e4d0070

793.*

793.vbb935f9be778

794.*

794.v8a62ee91dc70

795.*

795.vd5903dae1139

797.*

797.v31f530348574

799.*

799.va4c741108611

801.*

801.v37f3eab68cf0

802.*

802.vbac7a8a5d5e2

803.*

803.vef83d334600f

804.*

804.ve77d45cc9464

805.*

805.v424cc2981d7a

806.*

806.vae775cde5efa

808.*

808.v9d1999587120

810.*

810.v0a97a847315a

813.*

813.v8ae017133e51

815.*

815.vf2f07da070ee

816.*

816.v27bbb474b2b2

822.*

822.v3a18fc3d2de1

824.*

824.v31b_9c29f67fd

825.*

825.v470cb_9e7361a_

842.*

842.v9fedb_4cc1b_e9

845.*

845.v35ee7c5570db_

846.*

846.v5a_f7e3dce959

851.*

851.v16b_dcb_e85c85

852.*

852.v8d35f0960a_43

azure-vm-agents-0.*

azure-vm-agents-0.4.0
azure-vm-agents-0.4.1
azure-vm-agents-0.4.2
azure-vm-agents-0.4.3
azure-vm-agents-0.4.4
azure-vm-agents-0.4.5
azure-vm-agents-0.4.5.1
azure-vm-agents-0.4.6
azure-vm-agents-0.4.7
azure-vm-agents-0.4.7.1
azure-vm-agents-0.4.8
azure-vm-agents-0.5.0
azure-vm-agents-0.6.0
azure-vm-agents-0.6.1
azure-vm-agents-0.6.2
azure-vm-agents-0.7.0
azure-vm-agents-0.7.1
azure-vm-agents-0.7.2
azure-vm-agents-0.7.2.1
azure-vm-agents-0.7.3
azure-vm-agents-0.7.4
azure-vm-agents-0.7.5
azure-vm-agents-0.8.0
azure-vm-agents-0.8.1
azure-vm-agents-0.9.0
azure-vm-agents-0.9.0-preview

azure-vm-agents-1.*

azure-vm-agents-1.0.0
azure-vm-agents-1.0.1
azure-vm-agents-1.1.0
azure-vm-agents-1.1.1
azure-vm-agents-1.2.0
azure-vm-agents-1.2.1
azure-vm-agents-1.2.2
azure-vm-agents-1.3.0
azure-vm-agents-1.4.0
azure-vm-agents-1.4.1
azure-vm-agents-1.5.0
azure-vm-agents-1.5.1
azure-vm-agents-1.5.2
azure-vm-agents-1.5.3

v0.*

v0.9.1-PREVIEW