logo

CVE-2018-1999041 com.tinfoilsecurity.plugins:tinfoil-scan

Package

Manager: maven
Name: com.tinfoilsecurity.plugins:tinfoil-scan
Vulnerable Version: >=0 <2.0

Severity

Level: Medium

CVSS v3.1: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

CVSS v4.0: CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N

EPSS: 0.00015 pctl0.02252

Details

Exposure of sensitive information vulnerability An exposure of sensitive information vulnerability exists in Jenkins Tinfoil Security Plugin 1.6.1 and earlier in TinfoilScanRecorder.java that allows attackers with file system access to the Jenkins master to obtain the API secret key stored in this plugin's configuration.

Metadata

Created: 2022-05-14T02:57:33Z
Modified: 2022-11-01T22:31:50Z
Source: https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-68qx-whxm-h4c4/GHSA-68qx-whxm-h4c4.json
CWE IDs: ["CWE-200"]
Alternative ID: GHSA-68qx-whxm-h4c4
Finding: F038
Auto approve: 1