{"dataType":"CVE_RECORD","dataVersion":"5.1","cveMetadata":{"cveId":"CVE-2023-32262","assignerOrgId":"f81092c5-7f14-476d-80dc-24857f90be84","state":"PUBLISHED","assignerShortName":"OpenText","dateReserved":"2023-05-05T14:42:20.152Z","datePublished":"2023-07-19T15:56:32.548Z","dateUpdated":"2024-10-21T13:05:07.646Z"},"containers":{"cna":{"affected":[{"defaultStatus":"unaffected","product":"Dimensions CM","vendor":"Micro Focus","versions":[{"lessThanOrEqual":"0.9.3","status":"affected","version":"0.8.17","versionType":"semver"}]}],"credits":[{"lang":"en","type":"finder","user":"00000000-0000-4000-9000-000000000000","value":"Alvaro MuÃ±oz (@pwntester), GitHub Security Lab"}],"descriptions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"\n\n<span style=\"background-color: rgb(255, 255, 255);\">A potential vulnerability has been identified in the Micro Focus Dimensions CM Plugin for Jenkins. The vulnerability allows attackers with Item/Configure permission to access and capture credentials they are not entitled to.</span><br><span style=\"background-color: rgb(255, 255, 255);\">See the following Jenkins security advisory for details:</span><ul><li><a target=\"_blank\" rel=\"nofollow\" href=\"https://www.jenkins.io/security/advisory/2023-06-14/\"><i>https://www.jenkins.io/security/advisory/2023-06-14/</i></a></li></ul>\n\n"}],"value":"\nA potential vulnerability has been identified in the Micro Focus Dimensions CM Plugin for Jenkins. The vulnerability allows attackers with Item/Configure permission to access and capture credentials they are not entitled to.\nSee the following Jenkins security advisory for details:  *   https://www.jenkins.io/security/advisory/2023-06-14/ https://www.jenkins.io/security/advisory/2023-06-14/ \n\n\n\n\n"}],"impacts":[{"descriptions":[{"lang":"en","value":"Remote â€“ Potential exposure of system-scoped credentials"}]}],"metrics":[{"cvssV3_1":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":4.3,"baseSeverity":"MEDIUM","confidentialityImpact":"LOW","integrityImpact":"NONE","privilegesRequired":"LOW","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","version":"3.1"},"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}]}],"providerMetadata":{"orgId":"f81092c5-7f14-476d-80dc-24857f90be84","shortName":"OpenText","dateUpdated":"2023-07-19T15:56:32.548Z"},"references":[{"url":"https://www.jenkins.io/security/advisory/2023-06-14/"},{"url":"https://plugins.jenkins.io/dimensionsscm/"},{"url":"https://portal.microfocus.com/s/article/KM000019298"}],"solutions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"\n\n<span style=\"background-color: rgb(255, 255, 255);\">Micro Focus has resolved the vulnerability in the latest release of the Dimensions CM Plugin for Jenkins (version 0.9.3.1):<br></span><a target=\"_blank\" rel=\"nofollow\" href=\"https://plugins.jenkins.io/dimensionsscm/\"><i><br>https://plugins.jenkins.io/dimensionsscm/</i></a><span style=\"background-color: rgb(255, 255, 255);\"><br></span><br>"}],"value":"\nMicro Focus has resolved the vulnerability in the latest release of the Dimensions CM Plugin for Jenkins (version 0.9.3.1):\n \nhttps://plugins.jenkins.io/dimensionsscm/ https://plugins.jenkins.io/dimensionsscm/ \n\n"}],"source":{"discovery":"UNKNOWN"},"title":"Dimensions CM Plugin for Jenkins 0.8.17 â€“ 0.9.3","x_generator":{"engine":"Vulnogram 0.1.0-dev"}},"adp":[{"providerMetadata":{"orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE","dateUpdated":"2024-08-02T15:10:24.016Z"},"title":"CVE Program Container","references":[{"url":"https://www.jenkins.io/security/advisory/2023-06-14/","tags":["x_transferred"]},{"url":"https://plugins.jenkins.io/dimensionsscm/","tags":["x_transferred"]},{"url":"https://portal.microfocus.com/s/article/KM000019298","tags":["x_transferred"]}]},{"metrics":[{"other":{"type":"ssvc","content":{"timestamp":"2024-10-21T13:04:16.808847Z","id":"CVE-2023-32262","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2024-10-21T13:05:07.646Z"}}]}}