Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-6cr3-cm5h-8q96

Опубликовано: 14 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 4.3

Описание

Jenkins Exposes Sensitive Information via API URL

The API URL computer/(master)/api/xml in Jenkins before 2.3 and LTS before 1.651.2 allows remote authenticated users with extended read permission for the master node to obtain sensitive information about the global configuration via unspecified vectors.

Пакеты

Наименование

org.jenkins-ci.main:jenkins-core

maven
Затронутые версииВерсия исправления

>= 1.652, < 2.3

2.3

Наименование

org.jenkins-ci.main:jenkins-core

maven
Затронутые версииВерсия исправления

< 1.651.2

1.651.2

EPSS

Процентиль: 28%
0.00099
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-200

Связанные уязвимости

CVSS3: 4.3
ubuntu
больше 9 лет назад

The API URL computer/(master)/api/xml in Jenkins before 2.3 and LTS before 1.651.2 allows remote authenticated users with extended read permission for the master node to obtain sensitive information about the global configuration via unspecified vectors.

redhat
больше 9 лет назад

The API URL computer/(master)/api/xml in Jenkins before 2.3 and LTS before 1.651.2 allows remote authenticated users with extended read permission for the master node to obtain sensitive information about the global configuration via unspecified vectors.

CVSS3: 4.3
nvd
больше 9 лет назад

The API URL computer/(master)/api/xml in Jenkins before 2.3 and LTS before 1.651.2 allows remote authenticated users with extended read permission for the master node to obtain sensitive information about the global configuration via unspecified vectors.

CVSS3: 4.3
debian
больше 9 лет назад

The API URL computer/(master)/api/xml in Jenkins before 2.3 and LTS be ...

EPSS

Процентиль: 28%
0.00099
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-200