Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-rchx-rvh2-vx5j

Опубликовано: 26 июл. 2023
Источник: github
Github: Прошло ревью
CVSS3: 6.1

Описание

Credential leakage in Jenkins Plug-in for ServiceNow

A cross-site request forgery vulnerability exists in versions of the Jenkins Plug-in for ServiceNow DevOps prior to 1.38.1 that, if exploited successfully, could cause the unwanted exposure of sensitive information. To address this issue, apply the 1.38.1 version of the Jenkins plug-in for ServiceNow DevOps on your Jenkins server. No changes are required on your instances of the Now Platform.

Пакеты

Наименование

io.jenkins.plugins:servicenow-devops

maven
Затронутые версииВерсия исправления

< 1.38.1

1.38.1

EPSS

Процентиль: 10%
0.00035
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-200
CWE-352

Связанные уязвимости

CVSS3: 6.1
nvd
больше 2 лет назад

A cross-site request forgery vulnerability exists in versions of the Jenkins Plug-in for ServiceNow DevOps prior to 1.38.1 that, if exploited successfully, could cause the unwanted exposure of sensitive information. To address this issue, apply the 1.38.1 version of the Jenkins plug-in for ServiceNow DevOps on your Jenkins server. No changes are required on your instances of the Now Platform.

EPSS

Процентиль: 10%
0.00035
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-200
CWE-352