ZeroHour

CVE-2022-36896

CVSS 3.1
6.5 medium
EPSS
<1%p51
Published
()
Modified
Description

A missing permission check in Jenkins Compuware Source Code Download for Endevor, PDS, and ISPW Plugin 2.0.12 and earlier allows attackers with Overall/Read permission to enumerate hosts and ports of Compuware configurations and credentials IDs of credentials stored in Jenkins.

Vendors
jenkins
Products
compuware source code download for endevor\, pds\, and ispw
Weakness
CWE-862
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.