Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:30875
HistoryJun 08, 2021 - 12:38 p.m.

Information Disclosure

2021-06-0812:38:33
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
10

0.001 Low

EPSS

Percentile

22.0%

Jenkins Config File Provider Plugin is vulnerable to information disclosure. It does not perform permission checks in several HTTP endpoints, attackers with Overall/Read permission to enumerate configuration file IDs. A flaw was found in the config-file-provider Jenkins plugin. The plugin does not perform permission checks in several HTTP endpoints, as a consequence an attacker with Overall/Read permission is allowed to enumerate configuration file IDs.

0.001 Low

EPSS

Percentile

22.0%