PT-2018-9396 · Jenkins · Jenkins Aws Codedeploy Plugin+1

Oleg Nenashev

·

Published

2018-07-09

·

Updated

2022-05-14

·

CVE-2018-1000402

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Jenkins AWS CodeDeploy Plugin versions 1.19 and earlier
Description The issue is related to a File and Directory Information Exposure that can result in the disclosure of environment variables. This is due to a vulnerability in the AWSCodeDeployPublisher.java file.
Recommendations For Jenkins AWS CodeDeploy Plugin versions 1.19 and earlier, update to version 1.20 or later to resolve the issue.

Fix

Insufficiently Protected Credentials

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-1000402
GHSA-644J-JCC4-CRX7

Affected Products

Jenkins
Jenkins Aws Codedeploy Plugin