Missing permission checks in Jenkins CONS3RT Plugin allow enumerating credentials IDs
        
  Moderate severity
        
          GitHub Reviewed
      
        Published
          Sep 22, 2022 
          to the GitHub Advisory Database
          •
          Updated Jan 31, 2023 
      
  
Description
        Published by the National Vulnerability Database
      Sep 21, 2022 
    
  
        Published to the GitHub Advisory Database
      Sep 22, 2022 
    
  
        Reviewed
      Dec 6, 2022 
    
  
        Last updated
      Jan 31, 2023 
    
  
CONS3RT Plugin 1.0.0 and earlier does not perform permission checks in several HTTP endpoints.
This allows attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins. Those can be used as part of an attack to capture the credentials using another vulnerability.
References