CVE-2018-1999041 – com.tinfoilsecurity.plugins:tinfoil-scan
Package
Manager: maven
Name: com.tinfoilsecurity.plugins:tinfoil-scan
Vulnerable Version: >=0 <2.0
Severity
Level: Medium
CVSS v3.1: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CVSS v4.0: CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
EPSS: 0.00015 pctl0.02252
Details
Exposure of sensitive information vulnerability An exposure of sensitive information vulnerability exists in Jenkins Tinfoil Security Plugin 1.6.1 and earlier in TinfoilScanRecorder.java that allows attackers with file system access to the Jenkins master to obtain the API secret key stored in this plugin's configuration.
Metadata
Created: 2022-05-14T02:57:33Z
Modified: 2022-11-01T22:31:50Z
Source: https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-68qx-whxm-h4c4/GHSA-68qx-whxm-h4c4.json
CWE IDs: ["CWE-200"]
Alternative ID: GHSA-68qx-whxm-h4c4
Finding: F038
Auto approve: 1