PT-2014-3100 · Jenkins · Jenkins Subversion Plugin

Lennart Starr

·

Published

2014-05-08

·

Updated

2023-02-13

·

CVE-2013-6372

CVSS v4.0

5.1

Medium

VectorAV:L/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Jenkins Subversion plugin versions prior to 1.54
Description The issue allows local users to obtain passwords and SSH private keys by reading a subversion.credentials file, due to the storage of credentials using base64 encoding.
Recommendations For versions prior to 1.54, update to version 1.54 or later to resolve the issue.

Exploit

Fix

Inadequate Encryption Strength

Weakness Enumeration

Related Identifiers

CVE-2013-6372
GHSA-C4FR-GX5W-8QF2

Affected Products

Jenkins Subversion Plugin