Описание
Jenkins 2.393 and earlier, LTS 2.375.3 and earlier prints an error stack trace on agent-related pages when agent connections are broken, potentially revealing information about Jenkins configuration that is otherwise inaccessible to attackers.
A flaw was found in Jenkins. The affected version of Jenkins prints an error stack trace on agent-related pages when agent connections are broken. This stack trace may contain information about Jenkins configuration that is otherwise inaccessible to attackers.
Отчет
OpenShift 3.11 is already in the ELS support model phase. The Jenkins components are out of the scope of the ELS support; hence OpenShift 3.11 Jenkins component is marked in this CVE as Out of Support Scope.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat OpenShift Container Platform 3.11 | jenkins | Out of support scope | ||
| OCP-Tools-4.12-RHEL-8 | jenkins | Fixed | RHSA-2023:3195 | 18.05.2023 |
| OCP-Tools-4.12-RHEL-8 | jenkins | Fixed | RHSA-2023:6172 | 30.10.2023 |
| OCP-Tools-4.12-RHEL-8 | jenkins | Fixed | RHSA-2024:0778 | 12.02.2024 |
| OCP-Tools-4.13-RHEL-8 | jenkins | Fixed | RHSA-2023:3299 | 24.05.2023 |
| OCP-Tools-4.13-RHEL-8 | jenkins | Fixed | RHSA-2023:3622 | 15.06.2023 |
| OpenShift Developer Tools and Services for OCP 4.11 | jenkins | Fixed | RHSA-2023:3198 | 17.05.2023 |
| OpenShift Developer Tools and Services for OCP 4.11 | jenkins | Fixed | RHSA-2023:3663 | 19.06.2023 |
| OpenShift Developer Tools and Services for OCP 4.11 | jenkins | Fixed | RHSA-2023:6171 | 30.10.2023 |
| OpenShift Developer Tools and Services for OCP 4.11 | jenkins | Fixed | RHSA-2024:0775 | 12.02.2024 |
Показывать по
Дополнительная информация
Статус:
EPSS
5.3 Medium
CVSS3
Связанные уязвимости
Jenkins 2.393 and earlier, LTS 2.375.3 and earlier prints an error stack trace on agent-related pages when agent connections are broken, potentially revealing information about Jenkins configuration that is otherwise inaccessible to attackers.
Jenkins 2.393 and earlier, LTS 2.375.3 and earlier prints an error sta ...
Information disclosure through error stack traces related to agents
EPSS
5.3 Medium
CVSS3