Description
An exposure of sensitive information vulnerability exists in Jenkins Anchore Container Image Scanner Plugin 10.16 and earlier in AnchoreBuilder.java that allows attackers with Item/ExtendedRead permission or file system access to the Jenkins master to obtain the password stored in this plugin's configuration.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-5544 | An exposure of sensitive information vulnerability exists in Jenkins Anchore Container Image Scanner Plugin 10.16 and earlier in AnchoreBuilder.java that allows attackers with Item/ExtendedRead permission or file system access to the Jenkins master to obtain the password stored in this plugin's configuration. |
Github GHSA |
GHSA-w9v7-7mq5-p27c | Exposure of sensitive information in Anchore Container Image Scanner Jenkins Plugin |
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-09-17T01:07:10.172Z
Reserved: 2018-08-01T00:00:00.000Z
Link: CVE-2018-1999033
No data.
Status : Modified
Published: 2018-08-01T13:29:00.733
Modified: 2024-11-21T03:57:06.047
Link: CVE-2018-1999033
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA