VYPR
Medium severity6.5NVD Advisory· Published Oct 25, 2023· Updated Jun 17, 2026

CVE-2023-46651

CVE-2023-46651

Description

Jenkins Warnings Plugin 10.5.0 and earlier does not set the appropriate context for credentials lookup, allowing attackers with Item/Configure permission to access and capture credentials they are not entitled to. This fix has been backported to 10.4.1.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
io.jenkins.plugins:warnings-ngMaven
>= 10.5.0, < 10.5.110.5.1
io.jenkins.plugins:warnings-ngMaven
< 10.4.110.4.1

Affected products

2

Patches

Vulnerability mechanics

References

6

News mentions

1