Описание
Jenkins is missing a permission check on password fields
A missing permission check in Jenkins 2.540 and earlier, LTS 2.528.2 and earlier allows attackers with View/Read permission to view encrypted password values in views.
Пакеты
org.jenkins-ci.main:jenkins-core
>= 2.529, < 2.541
2.541
org.jenkins-ci.main:jenkins-core
< 2.528.3
2.528.3
Связанные уязвимости
A missing permission check in Jenkins 2.540 and earlier, LTS 2.528.2 and earlier allows attackers with View/Read permission to view encrypted password values in views.
A missing permission check in Jenkins 2.540 and earlier, LTS 2.528.2 and earlier allows attackers with View/Read permission to view encrypted password values in views.
Уязвимость сервера автоматизации Jenkins, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации