Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-92rv-mvmj-47qh

Опубликовано: 14 мая 2022
Источник: github
Github: Прошло ревью
CVSS4: 2.3
CVSS3: 4.2

Описание

Jenkins GitHub Pull Request Builder Plugin credential capture vulnerability

A exposure of sensitive information vulnerability exists in Jenkins GitHub Pull Request Builder Plugin 1.41.0 and older in GhprbGitHubAuth.java that allows attackers with Overall/Read access to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins. Additionally, these form validation methods did not require POST requests, resulting in a CSRF vulnerability. As of version 1.42.0, these form validation methods require POST requests and Overall/Administer permissions.

Пакеты

Наименование

org.jenkins-ci.plugins:ghprb

maven
Затронутые версииВерсия исправления

<= 1.41.0

1.42.0

EPSS

Процентиль: 27%
0.00094
Низкий

2.3 Low

CVSS4

4.2 Medium

CVSS3

Дефекты

CWE-200

Связанные уязвимости

CVSS3: 6.5
nvd
больше 7 лет назад

A exposure of sensitive information vulnerability exists in Jenkins GitHub Pull Request Builder Plugin 1.41.0 and older in GhprbGitHubAuth.java that allows attackers with Overall/Read access to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.

EPSS

Процентиль: 27%
0.00094
Низкий

2.3 Low

CVSS4

4.2 Medium

CVSS3

Дефекты

CWE-200