Jenkins Script Security Plugin 1189.vb_a_b_7c8fd5fde and earlier stores whole-script approvals as the SHA-1 hash of the script, making it vulnerable to collision attacks.
Metrics
Affected Vendors & Products
Advisories
Source | ID | Title |
---|---|---|
![]() |
EUVD-2022-7334 | Jenkins Script Security Plugin 1189.vb_a_b_7c8fd5fde and earlier stores whole-script approvals as the SHA-1 hash of the script, making it vulnerable to collision attacks. |
![]() |
GHSA-fv42-mx39-6fpw | Whole-script approval in Jenkins Script Security Plugin vulnerable to SHA-1 collisions |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.

Status: PUBLISHED
Assigner: jenkins
Published:
Updated: 2024-08-03T14:09:57.037Z
Reserved: 2022-11-14T00:00:00
Link: CVE-2022-45379

No data.

Status : Modified
Published: 2022-11-15T20:15:11.390
Modified: 2024-11-21T07:29:08.990
Link: CVE-2022-45379


No data.