QID 996709

Date Published: 2024-01-16

QID 996709: Java (Maven) Security Update for org.jvnet.hudson.plugins:perforce (GHSA-jrhw-r343-pjwj)

An exposure of sensitive information vulnerability exists in Jenkins Perforce Plugin version 1.3.36 and older in PerforcePasswordEncryptor.java that allows attackers with insufficient permission to obtain Perforce passwords configured in jobs to obtain them

Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.

  • CVSS V3 rated as High - 6.5 severity.
  • CVSS V2 rated as Medium - 4 severity.
  • Solution
    Refer to Github security advisory GHSA-jrhw-r343-pjwj for updates and patch information.
    Vendor References

    CVEs related to QID 996709

    Software Advisories
    Advisory ID Software Component Link