Lucene search

K
prionPRIOn knowledge basePRION:CVE-2023-43494
HistorySep 20, 2023 - 5:15 p.m.

Code injection

2023-09-2017:15:00
PRIOn knowledge base
www.prio-n.com
22
jenkins
code injection
vulnerability
lts
sensitive build variables
build history widget
attackers
item read permission

4.7 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

13.4%

Jenkins 2.50 through 2.423 (both inclusive), LTS 2.60.1 through 2.414.1 (both inclusive) does not exclude sensitive build variables (e.g., password parameter values) from the search in the build history widget, allowing attackers with Item/Read permission to obtain values of sensitive variables used in builds by iteratively testing different characters until the correct sequence is discovered.

4.7 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

13.4%