Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-x274-9m9r-fm5g

Опубликовано: 13 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 7.5

Описание

Jenkins does not Verify Checksums for Plugin Files

The Plugins Manager in Jenkins before 1.640 and LTS before 1.625.2 does not verify checksums for plugin files referenced in update site data, which makes it easier for man-in-the-middle attackers to execute arbitrary code via a crafted plugin.

Пакеты

Наименование

org.jenkins-ci.main:jenkins-core

maven
Затронутые версииВерсия исправления

< 1.625.2

1.625.2

Наименование

org.jenkins-ci.main:jenkins-core

maven
Затронутые версииВерсия исправления

>= 1.626, < 1.640

1.640

EPSS

Процентиль: 77%
0.0104
Низкий

7.5 High

CVSS3

Дефекты

CWE-345

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 10 лет назад

The Plugins Manager in Jenkins before 1.640 and LTS before 1.625.2 does not verify checksums for plugin files referenced in update site data, which makes it easier for man-in-the-middle attackers to execute arbitrary code via a crafted plugin.

redhat
около 10 лет назад

The Plugins Manager in Jenkins before 1.640 and LTS before 1.625.2 does not verify checksums for plugin files referenced in update site data, which makes it easier for man-in-the-middle attackers to execute arbitrary code via a crafted plugin.

CVSS3: 7.5
nvd
около 10 лет назад

The Plugins Manager in Jenkins before 1.640 and LTS before 1.625.2 does not verify checksums for plugin files referenced in update site data, which makes it easier for man-in-the-middle attackers to execute arbitrary code via a crafted plugin.

CVSS3: 7.5
debian
около 10 лет назад

The Plugins Manager in Jenkins before 1.640 and LTS before 1.625.2 doe ...

EPSS

Процентиль: 77%
0.0104
Низкий

7.5 High

CVSS3

Дефекты

CWE-345