Description
Jenkins Credentials Plugin 2.1.18 and earlier allowed users with permission to create or update credentials to confirm the existence of files on the Jenkins master with an attacker-specified path, and obtain the certificate content of files containing a PKCS#12 certificate.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-5823 | Jenkins Credentials Plugin 2.1.18 and earlier allowed users with permission to create or update credentials to confirm the existence of files on the Jenkins master with an attacker-specified path, and obtain the certificate content of files containing a PKCS#12 certificate. |
Github GHSA |
GHSA-xm94-9jw8-p6hw | Insertion of Sensitive Information into Externally-Accessible File or Directory in Jenkins Credentials Plugin |
References
History
No history.
Status: PUBLISHED
Assigner: jenkins
Published:
Updated: 2024-08-04T22:17:20.390Z
Reserved: 2019-03-29T00:00:00.000Z
Link: CVE-2019-10320
No data.
Status : Modified
Published: 2019-05-21T13:29:00.397
Modified: 2024-11-21T04:18:53.120
Link: CVE-2019-10320
OpenCVE Enrichment
No data.
EUVD
Github GHSA