Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-667q-vj58-rj88

Опубликовано: 14 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 4.3

Описание

Exposure of Sensitive Information to an Unauthorized Actor in Jenkins

A exposure of sensitive information vulnerability exists in Jenkins 2.137 and earlier, 2.121.2 and earlier in Computer.java that allows attackers With Overall/Read permission to access the connection log for any agent.

Пакеты

Наименование

org.jenkins-ci.main:jenkins-core

maven
Затронутые версииВерсия исправления

< 2.121.3

2.121.3

Наименование

org.jenkins-ci.main:jenkins-core

maven
Затронутые версииВерсия исправления

>= 2.122, < 2.138

2.138

EPSS

Процентиль: 41%
0.00188
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-200

Связанные уязвимости

CVSS3: 4.3
ubuntu
больше 7 лет назад

A exposure of sensitive information vulnerability exists in Jenkins 2.137 and earlier, 2.121.2 and earlier in Computer.java that allows attackers With Overall/Read permission to access the connection log for any agent.

CVSS3: 4.3
redhat
больше 7 лет назад

A exposure of sensitive information vulnerability exists in Jenkins 2.137 and earlier, 2.121.2 and earlier in Computer.java that allows attackers With Overall/Read permission to access the connection log for any agent.

CVSS3: 4.3
nvd
больше 7 лет назад

A exposure of sensitive information vulnerability exists in Jenkins 2.137 and earlier, 2.121.2 and earlier in Computer.java that allows attackers With Overall/Read permission to access the connection log for any agent.

CVSS3: 4.3
debian
больше 7 лет назад

A exposure of sensitive information vulnerability exists in Jenkins 2. ...

EPSS

Процентиль: 41%
0.00188
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-200