A exposure of sensitive information vulnerability exists in Jenkins 2.132 and earlier, 2.121.1 and earlier in Plugin.java that allows attackers to determine the date and time when a plugin HPI/JPI file was last extracted, which typically is the date of the most recent installation/upgrade.
Advisories
Source ID Title
EUVD EUVD EUVD-2022-2027 A exposure of sensitive information vulnerability exists in Jenkins 2.132 and earlier, 2.121.1 and earlier in Plugin.java that allows attackers to determine the date and time when a plugin HPI/JPI file was last extracted, which typically is the date of the most recent installation/upgrade.
Github GHSA Github GHSA GHSA-2pp9-r4rv-6p6j Exposure of Sensitive Information to an Unauthorized Actor in Jenkins
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-09-16T19:14:39.012Z

Reserved: 2018-07-23T00:00:00Z

Link: CVE-2018-1999006

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2018-07-23T19:29:00.470

Modified: 2024-11-21T03:57:01.820

Link: CVE-2018-1999006

cve-icon Redhat

Severity : Moderate

Publid Date: 2018-07-18T00:00:00Z

Links: CVE-2018-1999006 - Bugzilla

cve-icon OpenCVE Enrichment

No data.

Weaknesses