Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:35184
HistoryApr 21, 2022 - 12:43 a.m.

Sensitive Information Disclosure

2022-04-2100:43:03
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
28

0.001 Low

EPSS

Percentile

28.5%

Jenkins Pipeline is vulnerable to sensitive information disclosure. It allows attackers with Item/Read permission to retrieve the default password parameter value from jobs. A flaw was found in Jenkins pipeline-build-step where it revealed password parameter default values when generating a pipeline script using the Pipeline snippet generator. This flaw allows attackers with item/read permission to retrieve the default password parameter value from jobs and compromises confidentiality.

0.001 Low

EPSS

Percentile

28.5%