4.3
CVE-2024-39459
- EPSS 0.16%
- Veröffentlicht 26.06.2024 17:15:27
- Zuletzt bearbeitet 10.10.2025 15:26:09
- Quelle jenkinsci-cert@googlegroups.co
- CVE-Watchlists
- Unerledigt
In rare cases Jenkins Plain Credentials Plugin 182.v468b_97b_9dcb_8 and earlier stores secret file credentials unencrypted (only Base64 encoded) on the Jenkins controller file system, where they can be viewed by users with access to the Jenkins controller file system (global credentials) or with Item/Extended Read permission (folder-scoped credentials).
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Jenkins ≫ Plain Credentials SwPlatformjenkins Version <= 182.v468b_97b_9dcb_8
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.16% | 0.376 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| 134c704f-9b21-4f2e-91b3-4a467353bcc0 | 4.3 | 2.8 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
|
CWE-922 Insecure Storage of Sensitive Information
The product stores sensitive information without properly limiting read or write access by unauthorized actors.