← Zuruck zu CVEs
CVE-2023-43494
MEDIUM4.3
Beschreibung
Jenkins 2.50 through 2.423 (both inclusive), LTS 2.60.1 through 2.414.1 (both inclusive) does not exclude sensitive build variables (e.g., password parameter values) from the search in the build history widget, allowing attackers with Item/Read permission to obtain values of sensitive variables used in builds by iteratively testing different characters until the correct sequence is discovered.
CVE Details
CVSS v3.1 Bewertung4.3
SchweregradMEDIUM
CVSS VektorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
AngriffsvektorNETWORK
KomplexitatLOW
Erforderliche PrivilegienLOW
BenutzerinteraktionNONE
Veroffentlicht9/20/2023
Zuletzt geandert11/21/2024
Quellenvd
Honeypot-Sichtungen0
Betroffene Produkte
jenkins:jenkins
Referenzen
http://www.openwall.com/lists/oss-security/2023/09/20/5(jenkinsci-cert@googlegroups.com)
https://www.jenkins.io/security/advisory/2023-09-20/#SECURITY-3261(jenkinsci-cert@googlegroups.com)
http://www.openwall.com/lists/oss-security/2023/09/20/5(af854a3a-2127-422b-91ae-364da2661108)
https://www.jenkins.io/security/advisory/2023-09-20/#SECURITY-3261(af854a3a-2127-422b-91ae-364da2661108)
IOC Korrelationen
Keine Korrelationen erfasst
This product uses data from the NVD API but is not endorsed or certified by the NVD.