CVE-2019-1003011
MEDIUM6.5EPSS 0.56%Jenkins Token Macro Plugin's recursive token expansion results in information disclosure and DoS
發布日:2022/5/13修改日:2024/2/16
描述
Jenkins Token Macro Plugin recursively applied token expansion. This could be used by users able to affect input to token expansion (such as change log messages), to inject additional tokens into the input, which would then be expanded, resulting in information disclosure (for example values of environment variables), or denial of service. Most tokens have been changed to no longer recursively apply token expansion.
受影響套件(1)
- Maven/org.jenkins-ci.plugins:token-macrofrom 0, < 2.6
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 3.1 | MEDIUM6.5 | CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
參考連結(5)
- ADVISORYhttps://nvd.nist.gov/vuln/detail/CVE-2019-1003011
- WEBhttps://access.redhat.com/errata/RHBA-2019:0326
- WEBhttps://access.redhat.com/errata/RHBA-2019:0327
- WEBhttps://github.com/jenkinsci/token-macro-plugin/commit/70163600031ea8d43833e6eea928f8fa2e44f96a
- WEBhttps://jenkins.io/security/advisory/2019-01-28/#SECURITY-1102