Lucene search

K
cveJenkinsCVE-2023-24440
HistoryJan 26, 2023 - 9:18 p.m.

CVE-2023-24440

2023-01-2621:18:17
CWE-319
jenkins
web.nvd.nist.gov
168
jenkins
jira
pipeline
plugin
cve-2023-24440
security vulnerability
private key exposure
nvd

CVSS3

5.5

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

AI Score

5.5

Confidence

High

EPSS

0

Percentile

13.2%

Jenkins JIRA Pipeline Steps Plugin 2.0.165.v8846cf59f3db and earlier transmits the private key in plain text as part of the global Jenkins configuration form, potentially resulting in their exposure.

Affected configurations

Nvd
Node
jenkinsjira_pipeline_stepsRange2.0.165.v8846cf59f3dbjenkins
VendorProductVersionCPE
jenkinsjira_pipeline_steps*cpe:2.3:a:jenkins:jira_pipeline_steps:*:*:*:*:*:jenkins:*:*

CNA Affected

[
  {
    "product": "Jenkins JIRA Pipeline Steps Plugin",
    "vendor": "Jenkins Project",
    "versions": [
      {
        "lessThanOrEqual": "2.0.165.v8846cf59f3db",
        "status": "affected",
        "version": "unspecified",
        "versionType": "custom"
      },
      {
        "lessThan": "unspecified",
        "status": "unknown",
        "version": "next of 2.0.165.v8846cf59f3db",
        "versionType": "custom"
      }
    ]
  }
]

CVSS3

5.5

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

AI Score

5.5

Confidence

High

EPSS

0

Percentile

13.2%

Related for CVE-2023-24440