← Back to CVE List

CVE-2022-20616

Published: 2022-01-12T20:15Z
Last Modified: 2024-11-21T06:43Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
Jenkins Credentials Binding Plugin 1.27 and earlier does not perform a permission check in a method implementing form validation, allowing attackers with Overall/Read access to validate if a credential ID refers to a secret file credential and whether it's a zip file. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt