PT-2019-2636 · Jenkins · Jenkins Credentials Plugin+1

Pankaj Upadhyay

+1

·

Publicado

2019-05-21

·

Atualizado

2023-10-25

·

CVE-2019-10320

CVSS v3.1

4.3

Média

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Jenkins Credentials Plugin versions 2.1.18 and earlier
Description The issue allows users with permission to create or update credentials to confirm the existence of files on the Jenkins master with an attacker-specified path and obtain the certificate content of files containing a PKCS#12 certificate. This can lead to information leakage about files and directories. An attacker can exploit this to create or update credentials and gain access to files containing a PKCS#12 certificate.
Recommendations For Jenkins Credentials Plugin versions 2.1.18 and earlier, update to a version later than 2.1.18 to resolve the issue. At the moment, there is no information about other specific fixes for this vulnerability.

Correção

Information Disclosure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2019-02522
CVE-2019-10320
GHSA-XM94-9JW8-P6HW
RHSA-2019:1636

Produtos afetados

Jenkins
Jenkins Credentials Plugin