Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-8486-h39x-cx2f

Опубликовано: 13 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 8.8

Описание

Jenkins Configuration as Code Plugin has Insufficiently Protected Credentials

A exposure of sensitive information vulnerability exists in Jenkins Configuration as Code Plugin 0.7-alpha and earlier in DataBoundConfigurator.java, Attribute.java, BaseConfigurator.java, ExtensionConfigurator.java that allows attackers with access to Jenkins log files to obtain the passwords configured using Configuration as Code Plugin.

Пакеты

Наименование

io.jenkins:configuration-as-code

maven
Затронутые версииВерсия исправления

< 0.8-alpha

0.8-alpha

EPSS

Процентиль: 16%
0.00051
Низкий

8.8 High

CVSS3

Дефекты

CWE-522

Связанные уязвимости

CVSS3: 8.8
nvd
больше 7 лет назад

A exposure of sensitive information vulnerability exists in Jenkins Configuration as Code Plugin 0.7-alpha and earlier in DataBoundConfigurator.java, Attribute.java, BaseConfigurator.java, ExtensionConfigurator.java that allows attackers with access to Jenkins log files to obtain the passwords configured using Configuration as Code Plugin.

EPSS

Процентиль: 16%
0.00051
Низкий

8.8 High

CVSS3

Дефекты

CWE-522