Описание
Due to an incomplete fix of CVE-2019-10343, Jenkins Configuration as Code Plugin 1.26 and earlier did not properly apply masking to some values expected to be hidden when logging the configuration being applied.
Ссылки
- Mailing ListThird Party Advisory
- Vendor Advisory
- Mailing ListThird Party Advisory
- Vendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 1.26 (включая)
cpe:2.3:a:jenkins:configuration_as_code:*:*:*:*:*:jenkins:*:*
EPSS
Процентиль: 5%
0.00022
Низкий
5.5 Medium
CVSS3
2.1 Low
CVSS2
Дефекты
CWE-532
Связанные уязвимости
CVSS3: 5.5
github
больше 3 лет назад
Insertion of Sensitive Information into Log File in Jenkins Configuration as Code Plugin
EPSS
Процентиль: 5%
0.00022
Низкий
5.5 Medium
CVSS3
2.1 Low
CVSS2
Дефекты
CWE-532