-
Notifications
You must be signed in to change notification settings - Fork 1
Description
Vulnerable Library - plain-credentials-1.8.jar
Allows use of plain strings and files as credentials.
Library home page: https://github.com/jenkinsci/plain-credentials-plugin
Path to dependency file: /pom.xml
Path to vulnerable library: /pom.xml
Found in HEAD commit: 1877bb107aa0075f76932009e919b9ced82b92b4
Vulnerabilities
| Vulnerability | Severity | Dependency | Type | Fixed in (plain-credentials version) | Remediation Possible** | |
|---|---|---|---|---|---|---|
| CVE-2024-39459 | 4.3 | plain-credentials-1.8.jar | Direct | org.jenkins-ci.plugins:plain-credentials: | ||
| 183.va_de8f1dd5a_2b_ | ✅ |
**In some cases, Remediation PR cannot be created automatically for a vulnerability despite the availability of remediation
Details
CVE-2024-39459
Vulnerable Library - plain-credentials-1.8.jar
Allows use of plain strings and files as credentials.
Library home page: https://github.com/jenkinsci/plain-credentials-plugin
Path to dependency file: /pom.xml
Path to vulnerable library: /pom.xml
Dependency Hierarchy:
- ❌ plain-credentials-1.8.jar (Vulnerable Library)
Found in HEAD commit: 1877bb107aa0075f76932009e919b9ced82b92b4
Found in base branch: master
Vulnerability Details
In rare cases Jenkins Plain Credentials Plugin 182.v468b_97b_9dcb_8 and earlier stores secret file credentials unencrypted (only Base64 encoded) on the Jenkins controller file system, where they can be viewed by users with access to the Jenkins controller file system (global) or with Item/Extended Read permission (folder-scoped credentials).
Publish Date: 2024-06-26
URL: CVE-2024-39459
CVSS 3 Score Details (4.3)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: Low
- User Interaction: None
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: Low
- Integrity Impact: None
- Availability Impact: None
Suggested Fix
Type: Upgrade version
Origin: https://www.jenkins.io/security/advisory/2024-06-26/#SECURITY-2495
Release Date: 2024-06-26
Fix Resolution: org.jenkins-ci.plugins:plain-credentials: 183.va_de8f1dd5a_2b_
⛑️ Automatic Remediation will be attempted for this issue.
⛑️Automatic Remediation will be attempted for this issue.