Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-jwfr-h6jp-9p2g

Опубликовано: 05 мая 2022
Источник: github
Github: Прошло ревью

Описание

Jenkins allows attackers to obtain the master cryptographic key

Unspecified vulnerability in Jenkins before 1.498, Jenkins LTS before 1.480.2, and Jenkins Enterprise 1.447.x before 1.447.6.1 and 1.466.x before 1.466.12.1, when a slave is attached and anonymous read access is enabled, allows remote attackers to obtain the master cryptographic key via unknown vectors.

Пакеты

Наименование

org.jenkins-ci.main:jenkins-core

maven
Затронутые версииВерсия исправления

>= 1.481, < 1.498

1.498

Наименование

org.jenkins-ci.main:jenkins-core

maven
Затронутые версииВерсия исправления

< 1.480.2

1.480.2

EPSS

Процентиль: 70%
0.00653
Низкий

Связанные уязвимости

ubuntu
почти 13 лет назад

Unspecified vulnerability in Jenkins before 1.498, Jenkins LTS before 1.480.2, and Jenkins Enterprise 1.447.x before 1.447.6.1 and 1.466.x before 1.466.12.1, when a slave is attached and anonymous read access is enabled, allows remote attackers to obtain the master cryptographic key via unknown vectors.

redhat
около 13 лет назад

Unspecified vulnerability in Jenkins before 1.498, Jenkins LTS before 1.480.2, and Jenkins Enterprise 1.447.x before 1.447.6.1 and 1.466.x before 1.466.12.1, when a slave is attached and anonymous read access is enabled, allows remote attackers to obtain the master cryptographic key via unknown vectors.

nvd
почти 13 лет назад

Unspecified vulnerability in Jenkins before 1.498, Jenkins LTS before 1.480.2, and Jenkins Enterprise 1.447.x before 1.447.6.1 and 1.466.x before 1.466.12.1, when a slave is attached and anonymous read access is enabled, allows remote attackers to obtain the master cryptographic key via unknown vectors.

debian
почти 13 лет назад

Unspecified vulnerability in Jenkins before 1.498, Jenkins LTS before ...

EPSS

Процентиль: 70%
0.00653
Низкий