Jenkins Build Publisher Plugin Information Disclosure Vulnerability
BID:101544
CVE-2017-1000387 |Info
Jenkins Build Publisher Plugin Information Disclosure Vulnerability
| Bugtraq ID: | 101544 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | Yes |
| Published: | Oct 23 2017 12:00AM |
| Updated: | Oct 23 2017 12:00AM |
| Credit: | Steve Marlowe <[email protected]> of Cisco ASIG |
| Vulnerable: |
Jenkins-Ci Build Publisher Plugin 1.20 Jenkins-Ci Build Publisher Plugin 1.19 |
| Not Vulnerable: |
Jenkins-Ci Build Publisher Plugin 1.22 |
Discussion
Jenkins Build Publisher Plugin Information Disclosure Vulnerability
Build Publisher Plugin for Jenkins is prone to an information-disclosure vulnerability.
Successful exploits may allow an attacker to obtain sensitive information that may lead to further attacks.
Build Publisher Plugin for Jenkins is prone to an information-disclosure vulnerability.
Successful exploits may allow an attacker to obtain sensitive information that may lead to further attacks.
Exploit / POC
Jenkins Build Publisher Plugin Information Disclosure Vulnerability
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Jenkins Build Publisher Plugin Information Disclosure Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Jenkins Build Publisher Plugin Information Disclosure Vulnerability
References:
References:
- Build Publisher Plugin Jenkins homepage (Jenkins)
- Jenkins CI Homepage (Jenkins CI)
- Jenkins Security Advisory 2017-10-23 (Jenkins)