QID 996414
Date Published: 2023-12-26
QID 996414: Java (Maven) Security Update for org.jenkins-ci.plugins:pam-auth (GHSA-xqwq-jxjh-wj82)
A missing permission check in Jenkins PAM Authentication Plugin 1.5 and earlier, except 1.4.1 in PamSecurityRealm.DescriptorImpl#doTest allowed users with Overall/Read permission to obtain limited information about the file /etc/shadow and the user Jenkins is running as.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-xqwq-jxjh-wj82 for updates and patch information.
Vendor References
- GHSA-xqwq-jxjh-wj82 -
github.com/advisories/GHSA-xqwq-jxjh-wj82
CVEs related to QID 996414
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-xqwq-jxjh-wj82 | org.jenkins-ci.plugins:pam-auth |
|