Launch Week Day 1: Announcing Security Design Review
UNKNOWN Maven

Jenkins allows Remote Users to Obtain Sensitive Information from a Plugin Code

GHSA-5xm3-48v5-6h7v · CVE-2014-3667

Published · Modified

Description

Jenkins before 1.583 and LTS before 1.565.3 does not properly prevent downloading of plugins, which allows remote authenticated users with the Overall/READ permission to obtain sensitive information by reading the plugin code.

Ready to move

Start Securing

Free, no credit card | First findings in minutes