CVE-2017-2603
15.05.2018, 21:29
Jenkins before versions 2.44, 2.32.2 is vulnerable to a user data leak in disconnected agents' config.xml API. This could leak sensitive data such as API tokens (SECURITY-362).Enginsight
Vendor | Product | Version |
---|---|---|
jenkins | jenkins | 𝑥 < 2.44 |
jenkins | jenkins | 𝑥 < 2.32.2 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
- CWE-325 - Missing Cryptographic StepThe product does not implement a required step in a cryptographic algorithm, resulting in weaker encryption than advertised by the algorithm.
- CWE-200 - Exposure of Sensitive Information to an Unauthorized ActorThe product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
References