Description
A cross-site request forgery vulnerability exists in versions of the Jenkins Plug-in for ServiceNow DevOps prior to 1.38.1 that, if exploited successfully, could cause the unwanted exposure of sensitive information. To address this issue, apply the 1.38.1 version of the Jenkins plug-in for ServiceNow DevOps on your Jenkins server. No changes are required on your instances of the Now Platform.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-2138 | A cross-site request forgery vulnerability exists in versions of the Jenkins Plug-in for ServiceNow DevOps prior to 1.38.1 that, if exploited successfully, could cause the unwanted exposure of sensitive information. To address this issue, apply the 1.38.1 version of the Jenkins plug-in for ServiceNow DevOps on your Jenkins server. No changes are required on your instances of the Now Platform. |
Github GHSA |
GHSA-rchx-rvh2-vx5j | Credential leakage in Jenkins Plug-in for ServiceNow |
References
History
Tue, 15 Oct 2024 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: SN
Published:
Updated: 2024-10-15T15:54:57.698Z
Reserved: 2023-06-26T15:47:10.176Z
Link: CVE-2023-3414
Updated: 2024-08-02T06:55:03.404Z
Status : Modified
Published: 2023-07-26T19:15:09.797
Modified: 2024-11-21T08:17:13.047
Link: CVE-2023-3414
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA