QID 997479
Date Published: 2024-02-26
QID 997479: Java (Maven) Security Update for de.eacg:ecs-publisher (GHSA-ffj8-w4rj-vr7v)
A vulnerability in Jenkins ECS Publisher Plugin 1.0.0 and earlier allows attackers with Item/Extended Read permission, or local file system access to the Jenkins home directory to obtain the API token configured in this plugin's configuration.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-ffj8-w4rj-vr7v for updates and patch information.
Vendor References
- GHSA-ffj8-w4rj-vr7v -
github.com/advisories/GHSA-ffj8-w4rj-vr7v
CVEs related to QID 997479
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-ffj8-w4rj-vr7v | de.eacg:ecs-publisher |
|