[MAVEN:GHSA-279F-QWGH-H5MP] Jenkins does not exclude sensitive build variables from search

Severity Moderate
Affected Packages 2
Fixed Packages 2
CVEs 1

Jenkins allows filtering builds in the build history widget by specifying an expression that searches for matching builds by name, description, parameter values, etc.

Jenkins 2.50 through 2.423 (both inclusive), LTS 2.60.1 through 2.414.1 (both inclusive) does not exclude sensitive build variables (e.g., password parameter values) from this search.

This allows attackers with Item/Read permission to obtain values of sensitive variables used in builds by iteratively testing different characters until the correct sequence is discovered.

Jenkins 2.424, LTS 2.414.2 excludes sensitive variables from this search.

Package Affected Version
pkg:maven/org.jenkins-ci.main/jenkins-core >= 2.415, < 2.424
pkg:maven/org.jenkins-ci.main/jenkins-core >= 2.50, < 2.414.2
ID
MAVEN:GHSA-279F-QWGH-H5MP
Severity
moderate
URL
https://github.com/advisories/GHSA-279f-qwgh-h5mp
Published
2023-09-20T18:30:21
(12 months ago)
Modified
2023-11-12T05:02:22
(10 months ago)
Rights
Maven Security Team
Other Advisories
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:maven/org.jenkins-ci.main/jenkins-core org.jenkins-ci.main jenkins-core >= 2.415 < 2.424
Fixed pkg:maven/org.jenkins-ci.main/jenkins-core org.jenkins-ci.main jenkins-core = 2.424
Affected pkg:maven/org.jenkins-ci.main/jenkins-core org.jenkins-ci.main jenkins-core >= 2.50 < 2.414.2
Fixed pkg:maven/org.jenkins-ci.main/jenkins-core org.jenkins-ci.main jenkins-core = 2.414.2
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...