Lucene search

K
cveJenkinsCVE-2023-43494
HistorySep 20, 2023 - 5:15 p.m.

CVE-2023-43494

2023-09-2017:15:11
jenkins
web.nvd.nist.gov
107
cve-2023-43494
jenkins
security
vulnerability
build history
sensitive variables
nvd

CVSS3

4.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

AI Score

4.6

Confidence

High

EPSS

0.001

Percentile

21.5%

Jenkins 2.50 through 2.423 (both inclusive), LTS 2.60.1 through 2.414.1 (both inclusive) does not exclude sensitive build variables (e.g., password parameter values) from the search in the build history widget, allowing attackers with Item/Read permission to obtain values of sensitive variables used in builds by iteratively testing different characters until the correct sequence is discovered.

Affected configurations

Nvd
Node
jenkinsjenkinsRange2.502.424-
OR
jenkinsjenkinsRange2.60.12.414.2lts
VendorProductVersionCPE
jenkinsjenkins*cpe:2.3:a:jenkins:jenkins:*:*:*:*:-:*:*:*
jenkinsjenkins*cpe:2.3:a:jenkins:jenkins:*:*:*:*:lts:*:*:*

CNA Affected

[
  {
    "defaultStatus": "affected",
    "product": "Jenkins",
    "vendor": "Jenkins Project",
    "versions": [
      {
        "lessThan": "2.50",
        "status": "unaffected",
        "version": "0",
        "versionType": "maven"
      },
      {
        "lessThan": "*",
        "status": "unaffected",
        "version": "2.424",
        "versionType": "maven"
      },
      {
        "lessThan": "2.414.*",
        "status": "unaffected",
        "version": "2.414.2",
        "versionType": "maven"
      }
    ]
  }
]

CVSS3

4.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

AI Score

4.6

Confidence

High

EPSS

0.001

Percentile

21.5%