Permissions, Privileges, and Access Controls in Credentials Binding - CVE-2022-20616
Published: January 13, 2022
Credentials Binding
Jenkins
Description
The vulnerability allows a remote attacker to gain access to sensitive information.
The vulnerability exists due to application does not properly impose security restrictions in a method implementing form validation. A remote authenticated attacker can validate if a credential ID refers to a secret file credential and whether it’s a zip file.