Описание
Jenkins allows Remote Users to Obtain Sensitive Information from a Plugin Code
Jenkins before 1.583 and LTS before 1.565.3 does not properly prevent downloading of plugins, which allows remote authenticated users with the Overall/READ permission to obtain sensitive information by reading the plugin code.
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2014-3667
- https://github.com/jenkinsci/jenkins/commit/f0a29b562e14d837912c6b35fa4e81478563813a
- https://access.redhat.com/errata/RHBA-2014:1630
- https://access.redhat.com/errata/RHSA-2016:0070
- https://access.redhat.com/security/cve/CVE-2014-3667
- https://bugzilla.redhat.com/show_bug.cgi?id=1147770
- https://wiki.jenkins-ci.org/display/SECURITY/Jenkins+Security+Advisory+2014-10-01
Пакеты
org.jenkins-ci.main:jenkins-core
>= 1.566, < 1.583
1.583
org.jenkins-ci.main:jenkins-core
< 1.565.3
1.565.3
Связанные уязвимости
Jenkins before 1.583 and LTS before 1.565.3 does not properly prevent downloading of plugins, which allows remote authenticated users with the Overall/READ permission to obtain sensitive information by reading the plugin code.
Jenkins before 1.583 and LTS before 1.565.3 does not properly prevent downloading of plugins, which allows remote authenticated users with the Overall/READ permission to obtain sensitive information by reading the plugin code.
Jenkins before 1.583 and LTS before 1.565.3 does not properly prevent downloading of plugins, which allows remote authenticated users with the Overall/READ permission to obtain sensitive information by reading the plugin code.
Jenkins before 1.583 and LTS before 1.565.3 does not properly prevent ...