PT-2018-9315 · Jenkins · Jenkins Github Pull Request Builder Plugin+1

Steve Marlowe

·

Publicado

2018-04-05

·

Atualizado

2022-05-14

·

CVE-2018-1000143

CVSS v3.1

3.1

Baixa

VetorAV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Jenkins GitHub Pull Request Builder Plugin versions 1.39.0 and older Jenkins GitHub Pull Request Builder Plugin versions prior to 1.32.1
Description A sensitive information exposure issue exists, allowing an attacker with local file system access to obtain GitHub credentials. The GitHub Pull Request Builder Plugin stored the webhook secret shared between Jenkins and GitHub in plain text, which could be retrieved by users with local file system access or Jenkins administrators. This could lead to exposure of passwords through various means, such as browser extensions or cross-site scripting vulnerabilities.
Recommendations For Jenkins GitHub Pull Request Builder Plugin versions 1.39.0 and older, update to version 1.32.1 or newer, which stores the webhook secret encrypted on disk. For Jenkins GitHub Pull Request Builder Plugin versions prior to 1.32.1, update to version 1.32.1 or newer to ensure the webhook secret is stored encrypted.

Correção

Information Disclosure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2018-1000143
GHSA-876J-4Q73-7F56

Produtos afetados

Jenkins
Jenkins Github Pull Request Builder Plugin