Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2014-3680

Опубликовано: 16 окт. 2014
Источник: nvd
CVSS2: 4
EPSS Низкий

Описание

Jenkins before 1.583 and LTS before 1.565.3 allows remote authenticated users with the Job/READ permission to obtain the default value for the password field of a parameterized job by reading the DOM.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:jenkins:jenkins:*:*:*:*:lts:*:*:*
Версия до 1.565.2 (включая)
Конфигурация 2
cpe:2.3:a:redhat:openshift:*:*:*:*:enterprise:*:*:*
Версия до 3.1 (включая)
Конфигурация 3
cpe:2.3:a:jenkins:jenkins:*:*:*:*:*:*:*:*
Версия до 1.582 (включая)

EPSS

Процентиль: 69%
0.01361
Низкий

4 Medium

CVSS2

Дефекты

CWE-200

Связанные уязвимости

ubuntu
почти 12 лет назад

Jenkins before 1.583 and LTS before 1.565.3 allows remote authenticated users with the Job/READ permission to obtain the default value for the password field of a parameterized job by reading the DOM.

redhat
почти 12 лет назад

Jenkins before 1.583 and LTS before 1.565.3 allows remote authenticated users with the Job/READ permission to obtain the default value for the password field of a parameterized job by reading the DOM.

debian
почти 12 лет назад

Jenkins before 1.583 and LTS before 1.565.3 allows remote authenticate ...

github
около 4 лет назад

Jenkins Exposure of Sensitive Information to an Unauthorized Actor vulnerability

EPSS

Процентиль: 69%
0.01361
Низкий

4 Medium

CVSS2

Дефекты

CWE-200