PT-2018-15220 · Jenkins · Jenkins Tinfoil Security Plugin+1
Viktor Gazdag
·
Published
2018-08-01
·
Updated
2022-05-14
·
CVE-2018-1999041
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Jenkins Tinfoil Security Plugin versions 1.6.1 and earlier
Description
An exposure of sensitive information issue exists that allows attackers with file system access to the Jenkins master to obtain the API secret key stored in the plugin's configuration, specifically in TinfoilScanRecorder.java.
Recommendations
For Jenkins Tinfoil Security Plugin versions 1.6.1 and earlier, consider restricting file system access to the Jenkins master to minimize the risk of exploitation. As a temporary workaround, restrict access to the TinfoilScanRecorder.java component until a patch is available.
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Jenkins
Jenkins Tinfoil Security Plugin