PT-2018-9315 · Jenkins · Jenkins Github Pull Request Builder Plugin+1
Steve Marlowe
·
Publicado
2018-04-05
·
Atualizado
2022-05-14
·
CVE-2018-1000143
CVSS v3.1
3.1
Baixa
| Vetor | AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Jenkins GitHub Pull Request Builder Plugin versions 1.39.0 and older
Jenkins GitHub Pull Request Builder Plugin versions prior to 1.32.1
Description
A sensitive information exposure issue exists, allowing an attacker with local file system access to obtain GitHub credentials. The GitHub Pull Request Builder Plugin stored the webhook secret shared between Jenkins and GitHub in plain text, which could be retrieved by users with local file system access or Jenkins administrators. This could lead to exposure of passwords through various means, such as browser extensions or cross-site scripting vulnerabilities.
Recommendations
For Jenkins GitHub Pull Request Builder Plugin versions 1.39.0 and older, update to version 1.32.1 or newer, which stores the webhook secret encrypted on disk.
For Jenkins GitHub Pull Request Builder Plugin versions prior to 1.32.1, update to version 1.32.1 or newer to ensure the webhook secret is stored encrypted.
Correção
Information Disclosure
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Jenkins
Jenkins Github Pull Request Builder Plugin