PT-2018-15220 · Jenkins · Jenkins Tinfoil Security Plugin+1

Viktor Gazdag

·

Published

2018-08-01

·

Updated

2022-05-14

·

CVE-2018-1999041

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Jenkins Tinfoil Security Plugin versions 1.6.1 and earlier
Description An exposure of sensitive information issue exists that allows attackers with file system access to the Jenkins master to obtain the API secret key stored in the plugin's configuration, specifically in TinfoilScanRecorder.java.
Recommendations For Jenkins Tinfoil Security Plugin versions 1.6.1 and earlier, consider restricting file system access to the Jenkins master to minimize the risk of exploitation. As a temporary workaround, restrict access to the TinfoilScanRecorder.java component until a patch is available.

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-1999041
GHSA-68QX-WHXM-H4C4

Affected Products

Jenkins
Jenkins Tinfoil Security Plugin