Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-qv6q-x9vr-w7j3

Опубликовано: 16 фев. 2022
Источник: github
Github: Прошло ревью
CVSS3: 4.3

Описание

Jenkins Pipeline: Groovy Plugin has Insufficiently Protected Credentials

Jenkins Pipeline: Groovy Plugin 2648.va9433432b33c and earlier includes password parameters from the original build in replayed builds.

This allows attackers with Run/Replay permission to obtain the values of password parameters passed to previous builds of a Pipeline.

Pipeline: Groovy Plugin 2656.vf7a_e7b_75a_457 does not allow builds containing password parameters to be replayed.

Пакеты

Наименование

org.jenkins-ci.plugins.workflow:workflow-cps

maven
Затронутые версииВерсия исправления

<= 2648.va9433432b33c

2656.vf7a_e7b_75a_457

EPSS

Процентиль: 30%
0.00112
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-319
CWE-522

Связанные уязвимости

CVSS3: 4.3
redhat
почти 4 года назад

Jenkins Pipeline: Groovy Plugin 2648.va9433432b33c and earlier includes password parameters from the original build in replayed builds, allowing attackers with Run/Replay permission to obtain the values of password parameters passed to previous builds of a Pipeline.

CVSS3: 4.3
nvd
почти 4 года назад

Jenkins Pipeline: Groovy Plugin 2648.va9433432b33c and earlier includes password parameters from the original build in replayed builds, allowing attackers with Run/Replay permission to obtain the values of password parameters passed to previous builds of a Pipeline.

EPSS

Процентиль: 30%
0.00112
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-319
CWE-522