PT-2019-11758 · Jenkins · Jenkins Configuration As Code Plugin+1

·

CVE-2019-10362

·

Publicado

2019-07-31

·

Atualizado

2023-10-25

CVSS v2.0

5.5

Média

VetorAV:N/AC:L/Au:S/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions Jenkins Configuration as Code Plugin versions 1.24 and earlier
Description The issue allows attackers with permission to change Jenkins system configuration to obtain the values of environment variables due to variable interpolation during configuration import when exporting. This occurs because values are not properly escaped, resulting in the exposure of sensitive information.
Recommendations For Jenkins Configuration as Code Plugin versions 1.24 and earlier, update to a version later than 1.24 to resolve the issue.

Correção

Improper Encoding or Escaping of Output

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2019-10362
GHSA-5R6P-P9R6-R326

Produtos afetados

Jenkins
Jenkins Configuration As Code Plugin