Lucene search

K
osvGoogleOSV:GHSA-R9Q2-3R6X-QMGP
HistoryMay 13, 2022 - 1:36 a.m.

Inadequate Encryption Strength in Jenkins

2022-05-1301:36:56
Google
osv.dev
11

0.001 Low

EPSS

Percentile

43.4%

Jenkins before versions 2.44 and 2.32.2 uses AES ECB block cipher mode without IV for encrypting secrets which makes Jenkins and the stored secrets vulnerable to unnecessary risks (SECURITY-304).

0.001 Low

EPSS

Percentile

43.4%