logo

CVE-2019-1003011 org.jenkins-ci.plugins:token-macro

Package

Manager: maven
Name: org.jenkins-ci.plugins:token-macro
Vulnerable Version: >=0 <2.6

Severity

Level: Medium

CVSS v3.1: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N

EPSS: 0.00589 pctl0.68212

Details

Jenkins Token Macro Plugin's recursive token expansion results in information disclosure and DoS Jenkins Token Macro Plugin recursively applied token expansion. This could be used by users able to affect input to token expansion (such as change log messages), to inject additional tokens into the input, which would then be expanded, resulting in information disclosure (for example values of environment variables), or denial of service. Most tokens have been changed to no longer recursively apply token expansion.

Metadata

Created: 2022-05-13T01:15:21Z
Modified: 2023-10-25T23:16:02Z
Source: https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-23h9-m55m-c5jp/GHSA-23h9-m55m-c5jp.json
CWE IDs: ["CWE-674"]
Alternative ID: GHSA-23h9-m55m-c5jp
Finding: F067
Auto approve: 1