Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-2pp9-r4rv-6p6j

Опубликовано: 14 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 4.3

Описание

Exposure of Sensitive Information to an Unauthorized Actor in Jenkins

A exposure of sensitive information vulnerability exists in Jenkins 2.132 and earlier, 2.121.1 and earlier in Plugin.java that allows attackers to determine the date and time when a plugin HPI/JPI file was last extracted, which typically is the date of the most recent installation/upgrade.

Пакеты

Наименование

org.jenkins-ci.main:jenkins-core

maven
Затронутые версииВерсия исправления

< 2.121.2

2.121.2

Наименование

org.jenkins-ci.main:jenkins-core

maven
Затронутые версииВерсия исправления

>= 2.122, < 2.132

2.132

EPSS

Процентиль: 37%
0.00161
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-200

Связанные уязвимости

CVSS3: 4.3
redhat
больше 7 лет назад

A exposure of sensitive information vulnerability exists in Jenkins 2.132 and earlier, 2.121.1 and earlier in Plugin.java that allows attackers to determine the date and time when a plugin HPI/JPI file was last extracted, which typically is the date of the most recent installation/upgrade.

CVSS3: 4.3
nvd
больше 7 лет назад

A exposure of sensitive information vulnerability exists in Jenkins 2.132 and earlier, 2.121.1 and earlier in Plugin.java that allows attackers to determine the date and time when a plugin HPI/JPI file was last extracted, which typically is the date of the most recent installation/upgrade.

CVSS3: 4.3
debian
больше 7 лет назад

A exposure of sensitive information vulnerability exists in Jenkins 2. ...

EPSS

Процентиль: 37%
0.00161
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-200