Lucene search

K
osvGoogleOSV:GHSA-JWFR-H6JP-9P2G
HistoryMay 05, 2022 - 2:48 a.m.

Jenkins allows attackers to obtain the master cryptographic key

2022-05-0502:48:30
Google
osv.dev
4

6.4 Medium

AI Score

Confidence

Low

0.007 Low

EPSS

Percentile

80.4%

Unspecified vulnerability in Jenkins before 1.498, Jenkins LTS before 1.480.2, and Jenkins Enterprise 1.447.x before 1.447.6.1 and 1.466.x before 1.466.12.1, when a slave is attached and anonymous read access is enabled, allows remote attackers to obtain the master cryptographic key via unknown vectors.

References

6.4 Medium

AI Score

Confidence

Low

0.007 Low

EPSS

Percentile

80.4%