Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-6cvm-v6qj-hjq9

Опубликовано: 13 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 8.8

Описание

CSRF vulnerability and missing permission checks in GitHub Plugin allowed capturing credentials

A exposure of sensitive information vulnerability exists in Jenkins GitHub Plugin 1.29.1 and earlier in GitHubTokenCredentialsCreator.java that allows attackers to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.

Пакеты

Наименование

com.coravy.hudson.plugins.github:github

maven
Затронутые версииВерсия исправления

<= 1.29.1

1.29.2

EPSS

Процентиль: 100%
0.93511
Критический

8.8 High

CVSS3

Дефекты

CWE-200

Связанные уязвимости

CVSS3: 4.2
redhat
больше 7 лет назад

A exposure of sensitive information vulnerability exists in Jenkins GitHub Plugin 1.29.1 and earlier in GitHubTokenCredentialsCreator.java that allows attackers to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.

CVSS3: 8.8
nvd
больше 7 лет назад

A exposure of sensitive information vulnerability exists in Jenkins GitHub Plugin 1.29.1 and earlier in GitHubTokenCredentialsCreator.java that allows attackers to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.

EPSS

Процентиль: 100%
0.93511
Критический

8.8 High

CVSS3

Дефекты

CWE-200