Description
A exposure of sensitive information vulnerability exists in Jenkins Gitlab Hook Plugin 1.4.2 and older in gitlab_notifier.rb, views/gitlab_notifier/global.erb that allows attackers with local Jenkins master file system access or control of a Jenkins administrator's web browser (e.g. malicious extension) to retrieve the configured Gitlab token.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-3038 | A exposure of sensitive information vulnerability exists in Jenkins Gitlab Hook Plugin 1.4.2 and older in gitlab_notifier.rb, views/gitlab_notifier/global.erb that allows attackers with local Jenkins master file system access or control of a Jenkins administrator's web browser (e.g. malicious extension) to retrieve the configured Gitlab token. |
Github GHSA |
GHSA-7p4p-v6hr-gp3m | Jenkins Gitlab Hook Plugin stores and displays GitLab API token in plain text |
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-09-16T16:53:10.883Z
Reserved: 2018-06-05T00:00:00.000Z
Link: CVE-2018-1000196
No data.
Status : Modified
Published: 2018-06-05T21:29:00.667
Modified: 2024-11-21T03:39:54.613
Link: CVE-2018-1000196
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA