Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-53jp-gmwc-jwf6

Опубликовано: 14 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 7.8

Описание

Exposure of Sensitive Information to an Unauthorized Actor in Jenkins

An information exposure vulnerability exists in Jenkins 2.145 and earlier, LTS 2.138.1 and earlier, and the Stapler framework used by these releases, in core/src/main/java/org/kohsuke/stapler/RequestImpl.java, core/src/main/java/hudson/model/Descriptor.java that allows attackers with Overall/Administer permission or access to the local file system to obtain credentials entered by users if the form submission could not be successfully processed.

Пакеты

Наименование

org.jenkins-ci.main:jenkins-core

maven
Затронутые версииВерсия исправления

<= 2.138.1

2.138.2

Наименование

org.jenkins-ci.main:jenkins-core

maven
Затронутые версииВерсия исправления

>= 2.140, <= 2.145

2.146

EPSS

Процентиль: 32%
0.00126
Низкий

7.8 High

CVSS3

Дефекты

CWE-200

Связанные уязвимости

CVSS3: 2.9
redhat
больше 7 лет назад

An information exposure vulnerability exists in Jenkins 2.145 and earlier, LTS 2.138.1 and earlier, and the Stapler framework used by these releases, in core/src/main/java/org/kohsuke/stapler/RequestImpl.java, core/src/main/java/hudson/model/Descriptor.java that allows attackers with Overall/Administer permission or access to the local file system to obtain credentials entered by users if the form submission could not be successfully processed.

CVSS3: 7.8
nvd
около 7 лет назад

An information exposure vulnerability exists in Jenkins 2.145 and earlier, LTS 2.138.1 and earlier, and the Stapler framework used by these releases, in core/src/main/java/org/kohsuke/stapler/RequestImpl.java, core/src/main/java/hudson/model/Descriptor.java that allows attackers with Overall/Administer permission or access to the local file system to obtain credentials entered by users if the form submission could not be successfully processed.

CVSS3: 7.8
debian
около 7 лет назад

An information exposure vulnerability exists in Jenkins 2.145 and earl ...

EPSS

Процентиль: 32%
0.00126
Низкий

7.8 High

CVSS3

Дефекты

CWE-200