QID 996873
Date Published: 2024-01-25
QID 996873: Java (Maven) Security Update for com.coravy.hudson.plugins.github:github (GHSA-v7g7-cmxx-wxw9)
A exposure of sensitive information vulnerability exists in Jenkins GitHub Plugin 1.29.0 and older in GitHubServerConfig.java that allows attackers with Overall/Read access to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-v7g7-cmxx-wxw9 for updates and patch information.
Vendor References
- GHSA-v7g7-cmxx-wxw9 -
github.com/advisories/GHSA-v7g7-cmxx-wxw9
CVEs related to QID 996873
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-v7g7-cmxx-wxw9 | com.coravy.hudson.plugins.github:github |
|