PT-2019-11758 · Jenkins · Jenkins Configuration As Code Plugin+1
CVSS v2.0
5.5
Média
| Vetor | AV:N/AC:L/Au:S/C:P/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Jenkins Configuration as Code Plugin versions 1.24 and earlier
Description
The issue allows attackers with permission to change Jenkins system configuration to obtain the values of environment variables due to variable interpolation during configuration import when exporting. This occurs because values are not properly escaped, resulting in the exposure of sensitive information.
Recommendations
For Jenkins Configuration as Code Plugin versions 1.24 and earlier, update to a version later than 1.24 to resolve the issue.
Correção
Improper Encoding or Escaping of Output
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Jenkins
Jenkins Configuration As Code Plugin