Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-jwfr-h6jp-9p2g

Опубликовано: 05 мая 2022
Источник: github
Github: Прошло ревью

Описание

Jenkins allows attackers to obtain the master cryptographic key

Unspecified vulnerability in Jenkins before 1.498, Jenkins LTS before 1.480.2, and Jenkins Enterprise 1.447.x before 1.447.6.1 and 1.466.x before 1.466.12.1, when a slave is attached and anonymous read access is enabled, allows remote attackers to obtain the master cryptographic key via unknown vectors.

Пакеты

Наименование

org.jenkins-ci.main:jenkins-core

maven
Затронутые версииВерсия исправления

>= 1.481, < 1.498

1.498

Наименование

org.jenkins-ci.main:jenkins-core

maven
Затронутые версииВерсия исправления

< 1.480.2

1.480.2

EPSS

Процентиль: 83%
0.02455
Низкий

Связанные уязвимости

ubuntu
больше 13 лет назад

Unspecified vulnerability in Jenkins before 1.498, Jenkins LTS before 1.480.2, and Jenkins Enterprise 1.447.x before 1.447.6.1 and 1.466.x before 1.466.12.1, when a slave is attached and anonymous read access is enabled, allows remote attackers to obtain the master cryptographic key via unknown vectors.

redhat
больше 13 лет назад

Unspecified vulnerability in Jenkins before 1.498, Jenkins LTS before 1.480.2, and Jenkins Enterprise 1.447.x before 1.447.6.1 and 1.466.x before 1.466.12.1, when a slave is attached and anonymous read access is enabled, allows remote attackers to obtain the master cryptographic key via unknown vectors.

nvd
больше 13 лет назад

Unspecified vulnerability in Jenkins before 1.498, Jenkins LTS before 1.480.2, and Jenkins Enterprise 1.447.x before 1.447.6.1 and 1.466.x before 1.466.12.1, when a slave is attached and anonymous read access is enabled, allows remote attackers to obtain the master cryptographic key via unknown vectors.

debian
больше 13 лет назад

Unspecified vulnerability in Jenkins before 1.498, Jenkins LTS before ...

EPSS

Процентиль: 83%
0.02455
Низкий