Unauthorized access to screen In org.jenkins-ci.plugins:github-oauth
Description
GitHub Authentication Plugin showed plain text client secret in configuration form An exposure of sensitive information vulnerability exists in Jenkins GitHub Authentication Plugin 0.29 and earlier in GithubSecurityRealm/config.jelly that allows attackers able to view a Jenkins administrator's web browser output, or control the browser (e.g. malicious extension) to retrieve the configured client secret.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
maven | 0.31 |
Aliases
1. 2. 3. 4.
References
1. 2.