Описание
Exposure of Sensitive Information to an Unauthorized Actor in Jenkins
Jenkins before versions 2.44 and 2.32.2 is vulnerable to a user data leak in disconnected agents' config.xml API. This could leak sensitive data such as API tokens (SECURITY-362).
Пакеты
org.jenkins-ci.main:jenkins-core
<= 2.32.1
2.32.2
org.jenkins-ci.main:jenkins-core
>= 2.34, <= 2.43
2.44
Связанные уязвимости
Jenkins before versions 2.44, 2.32.2 is vulnerable to a user data leak in disconnected agents' config.xml API. This could leak sensitive data such as API tokens (SECURITY-362).
Jenkins before versions 2.44, 2.32.2 is vulnerable to a user data leak in disconnected agents' config.xml API. This could leak sensitive data such as API tokens (SECURITY-362).
Jenkins before versions 2.44, 2.32.2 is vulnerable to a user data leak in disconnected agents' config.xml API. This could leak sensitive data such as API tokens (SECURITY-362).
Jenkins before versions 2.44, 2.32.2 is vulnerable to a user data leak ...