PT-2018-15220 · Jenkins · Jenkins Tinfoil Security Plugin+1
Viktor Gazdag
·
Publicado
2018-08-01
·
Atualizado
2022-05-14
·
CVE-2018-1999041
CVSS v3.1
5.5
Média
| Vetor | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Jenkins Tinfoil Security Plugin versions 1.6.1 and earlier
Description
An exposure of sensitive information issue exists that allows attackers with file system access to the Jenkins master to obtain the API secret key stored in the plugin's configuration, specifically in TinfoilScanRecorder.java.
Recommendations
For Jenkins Tinfoil Security Plugin versions 1.6.1 and earlier, consider restricting file system access to the Jenkins master to minimize the risk of exploitation. As a temporary workaround, restrict access to the TinfoilScanRecorder.java component until a patch is available.
Correção
Information Disclosure
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Jenkins
Jenkins Tinfoil Security Plugin