Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-cj2x-r74q-vcx9

Опубликовано: 26 июл. 2023
Источник: github
Github: Прошло ревью
CVSS3: 7.7

Описание

Missing authorization in Jenkins Plug-in for ServiceNow

A missing authorization vulnerability exists in versions of the Jenkins Plug-in for ServiceNow DevOps prior to 1.38.1 that, if exploited successfully, could cause the unwanted exposure of sensitive information. To address this issue, apply the 1.38.1 version of the Jenkins plug-in for ServiceNow DevOps on your Jenkins server. No changes are required on your instances of the Now Platform.

Пакеты

Наименование

io.jenkins.plugins:servicenow-devops

maven
Затронутые версииВерсия исправления

< 1.38.1

1.38.1

EPSS

Процентиль: 9%
0.00033
Низкий

7.7 High

CVSS3

Дефекты

CWE-862

Связанные уязвимости

CVSS3: 7.7
nvd
больше 2 лет назад

A missing authorization vulnerability exists in versions of the Jenkins Plug-in for ServiceNow DevOps prior to 1.38.1 that, if exploited successfully, could cause the unwanted exposure of sensitive information. To address this issue, apply the 1.38.1 version of the Jenkins plug-in for ServiceNow DevOps on your Jenkins server. No changes are required on your instances of the Now Platform.

EPSS

Процентиль: 9%
0.00033
Низкий

7.7 High

CVSS3

Дефекты

CWE-862