Launch Week Day 1: Announcing Security Design Review
UNKNOWN Maven

Jenkins Exposure of Sensitive Information to an Unauthorized Actor vulnerability

GHSA-8x8p-mfwv-9fjw · CVE-2014-3680

Published · Modified

Description

Jenkins before 1.583 and LTS before 1.565.3 allows remote authenticated users with the Job/READ permission to obtain the default value for the password field of a parameterized job by reading the DOM.

Ready to move

Start Securing

Free, no credit card | First findings in minutes