Jenkins JIRA Plugin allows users to select and use credentials with System scope
Moderate severity
GitHub Reviewed
Published
May 24, 2022
to the GitHub Advisory Database
•
Updated Dec 20, 2023
Description
Published by the National Vulnerability Database
Nov 21, 2019
Published to the GitHub Advisory Database
May 24, 2022
Reviewed
Dec 6, 2022
Last updated
Dec 20, 2023
Jenkins JIRA Plugin 3.0.10 and earlier does not declare the correct (folder) scope for per-folder Jira site definitions, allowing users to select and use credentials with System scope. Jira Plugin 3.0.11 defines the appropriate folder context for credential lookup. As a side effect, existing per-folder Jira sites may lose access to already configured System-scoped credentials, as if no credential was specified in the first place.
References