UNKNOWN Maven

Jenkins allows Remote Users to Obtain Sensitive Information from a Plugin Code

GHSA-5xm3-48v5-6h7v · CVE-2014-3667

Published · Modified

AI SAST

Find this class of vulnerability in your own code

Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.

Description

Jenkins before 1.583 and LTS before 1.565.3 does not properly prevent downloading of plugins, which allows remote authenticated users with the Overall/READ permission to obtain sensitive information by reading the plugin code.

Ready to move

Start Securing

Free, no credit card | First findings in minutes