Lucene search

K
nvd[email protected]NVD:CVE-2023-24440
HistoryJan 26, 2023 - 9:18 p.m.

CVE-2023-24440

2023-01-2621:18:17
CWE-319
web.nvd.nist.gov
6
jenkins
jira
pipeline steps plugin
private key exposure

CVSS3

5.5

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

EPSS

0

Percentile

13.2%

Jenkins JIRA Pipeline Steps Plugin 2.0.165.v8846cf59f3db and earlier transmits the private key in plain text as part of the global Jenkins configuration form, potentially resulting in their exposure.

Affected configurations

Nvd
Node
jenkinsjira_pipeline_stepsRange2.0.165.v8846cf59f3dbjenkins
VendorProductVersionCPE
jenkinsjira_pipeline_steps*cpe:2.3:a:jenkins:jira_pipeline_steps:*:*:*:*:*:jenkins:*:*

CVSS3

5.5

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

EPSS

0

Percentile

13.2%

Related for NVD:CVE-2023-24440