Lucene search

K
osvGoogleOSV:GHSA-393R-R9MQ-G9JV
HistoryMay 14, 2022 - 3:05 a.m.

Jenkins Configuration as Code Plugin vulnerable to Exposure of Sensitive Information

2022-05-1403:05:26
Google
osv.dev
10
jenkins
configuration
sensitive information

EPSS

0.001

Percentile

28.4%

A exposure of sensitive information vulnerability exists in Jenkins Configuration as Code Plugin 0.7-alpha and earlier in ConfigurationAsCode.java that allows attackers with Overall/Read access to obtain the YAML export of the Jenkins configuration. Version 0.8-alpha contains a fix for this issue.

EPSS

0.001

Percentile

28.4%

Related for OSV:GHSA-393R-R9MQ-G9JV