Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2018-1000410

Опубликовано: 09 янв. 2019
Источник: nvd
CVSS3: 7.8
CVSS2: 2.1
EPSS Низкий

Описание

An information exposure vulnerability exists in Jenkins 2.145 and earlier, LTS 2.138.1 and earlier, and the Stapler framework used by these releases, in core/src/main/java/org/kohsuke/stapler/RequestImpl.java, core/src/main/java/hudson/model/Descriptor.java that allows attackers with Overall/Administer permission or access to the local file system to obtain credentials entered by users if the form submission could not be successfully processed.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:jenkins:jenkins:*:*:*:*:lts:*:*:*
Версия до 2.138.1 (включая)
cpe:2.3:a:jenkins:jenkins:*:*:*:*:-:*:*:*
Версия до 2.145 (включая)

EPSS

Процентиль: 32%
0.00126
Низкий

7.8 High

CVSS3

2.1 Low

CVSS2

Дефекты

CWE-200

Связанные уязвимости

CVSS3: 2.9
redhat
больше 7 лет назад

An information exposure vulnerability exists in Jenkins 2.145 and earlier, LTS 2.138.1 and earlier, and the Stapler framework used by these releases, in core/src/main/java/org/kohsuke/stapler/RequestImpl.java, core/src/main/java/hudson/model/Descriptor.java that allows attackers with Overall/Administer permission or access to the local file system to obtain credentials entered by users if the form submission could not be successfully processed.

CVSS3: 7.8
debian
около 7 лет назад

An information exposure vulnerability exists in Jenkins 2.145 and earl ...

CVSS3: 7.8
github
больше 3 лет назад

Exposure of Sensitive Information to an Unauthorized Actor in Jenkins

EPSS

Процентиль: 32%
0.00126
Низкий

7.8 High

CVSS3

2.1 Low

CVSS2

Дефекты

CWE-200