Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-644j-jcc4-crx7

Опубликовано: 14 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 4.3

Описание

Jenkins AWS CodeDeploy Plugin has Insufficiently Protected Credentials

Jenkins project Jenkins AWS CodeDeploy Plugin version 1.19 and earlier contains a File and Directory Information Exposure vulnerability in AWSCodeDeployPublisher.java that can result in Disclosure of environment variables. This vulnerability appears to have been fixed in 1.20 and later.

Пакеты

Наименование

com.amazonaws:codedeploy

maven
Затронутые версииВерсия исправления

< 1.20

1.20

EPSS

Процентиль: 12%
0.00039
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-522

Связанные уязвимости

CVSS3: 4.3
nvd
больше 7 лет назад

Jenkins project Jenkins AWS CodeDeploy Plugin version 1.19 and earlier contains a File and Directory Information Exposure vulnerability in AWSCodeDeployPublisher.java that can result in Disclosure of environment variables. This vulnerability appears to have been fixed in 1.20 and later.

EPSS

Процентиль: 12%
0.00039
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-522