Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-393r-r9mq-g9jv

Опубликовано: 14 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 6.5

Описание

Jenkins Configuration as Code Plugin vulnerable to Exposure of Sensitive Information

A exposure of sensitive information vulnerability exists in Jenkins Configuration as Code Plugin 0.7-alpha and earlier in ConfigurationAsCode.java that allows attackers with Overall/Read access to obtain the YAML export of the Jenkins configuration. Version 0.8-alpha contains a fix for this issue.

Пакеты

Наименование

io.jenkins:configuration-as-code

maven
Затронутые версииВерсия исправления

< 0.8-alpha

0.8-alpha

EPSS

Процентиль: 21%
0.00069
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-200

Связанные уязвимости

CVSS3: 6.5
nvd
больше 7 лет назад

A exposure of sensitive information vulnerability exists in Jenkins Configuration as Code Plugin 0.7-alpha and earlier in ConfigurationAsCode.java that allows attackers with Overall/Read access to obtain the YAML export of the Jenkins configuration.

EPSS

Процентиль: 21%
0.00069
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-200