Description
An arbitrary file read vulnerability in Jenkins Google OAuth Credentials Plugin 0.9 and earlier allowed attackers able to configure jobs and credentials in Jenkins to obtain the contents of any file on the Jenkins master.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-3215 | An arbitrary file read vulnerability in Jenkins Google OAuth Credentials Plugin 0.9 and earlier allowed attackers able to configure jobs and credentials in Jenkins to obtain the contents of any file on the Jenkins master. |
Github GHSA |
GHSA-8qh4-fghr-6fxg | Improper Limitation of a Pathname to a Restricted Directory in Jenkins Google OAuth Credentials Plugin |
References
History
No history.
Status: PUBLISHED
Assigner: jenkins
Published:
Updated: 2024-08-04T22:24:18.704Z
Reserved: 2019-03-29T00:00:00.000Z
Link: CVE-2019-10436
No data.
Status : Modified
Published: 2019-10-16T14:15:11.277
Modified: 2024-11-21T04:19:08.173
Link: CVE-2019-10436
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA