Lucene search

K
alpinelinuxAlpine Linux Development TeamALPINE:CVE-2023-43494
HistorySep 20, 2023 - 5:15 p.m.

CVE-2023-43494

2023-09-2017:15:11
Alpine Linux Development Team
security.alpinelinux.org
9
jenkins
vulnerability
build history

0.0004 Low

EPSS

Percentile

13.4%

Jenkins 2.50 through 2.423 (both inclusive), LTS 2.60.1 through 2.414.1 (both inclusive) does not exclude sensitive build variables (e.g., password parameter values) from the search in the build history widget, allowing attackers with Item/Read permission to obtain values of sensitive variables used in builds by iteratively testing different characters until the correct sequence is discovered.

OSVersionArchitecturePackageVersionFilename
Alpine3.18-communitynoarchjenkins= 2.387.3-r0UNKNOWN
Alpine3.19-communitynoarchjenkins= 2.414.3-r0UNKNOWN

0.0004 Low

EPSS

Percentile

13.4%