Vulnerability Description
A potential vulnerability has been identified in the Micro Focus Dimensions CM Plugin for Jenkins. The vulnerability could be exploited to retrieve a login certificate if an authenticated user is duped into using an attacker-controlled Dimensions CM server. This vulnerability only applies when the Jenkins plugin is configured to use login certificate credentials. https://www.jenkins.io/security/advisory/2023-06-14/
CVSS Score
LOW
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Microfocus | Dimensions Cm | >= 0.8.17, <= 0.9.3 |
References
- https://plugins.jenkins.io/dimensionsscm/Product
- https://portal.microfocus.com/s/article/KM000019293Vendor Advisory
- https://plugins.jenkins.io/dimensionsscm/Product
- https://portal.microfocus.com/s/article/KM000019293Vendor Advisory
FAQ
What is CVE-2023-32263?
CVE-2023-32263 is a vulnerability with a CVSS score of 2.6 (LOW). A potential vulnerability has been identified in the Micro Focus Dimensions CM Plugin for Jenkins. The vulnerability could be exploited to retrieve a login certificate if an authenticated user is dup...
How severe is CVE-2023-32263?
CVE-2023-32263 has been rated LOW with a CVSS base score of 2.6/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-32263?
Check the references section above for vendor advisories and patch information. Affected products include: Microfocus Dimensions Cm.