Jenkins AsakusaSatellite Plugin 0.1.1 and earlier stores AsakusaSatellite API keys unencrypted in job config.xml files on the Jenkins controller where they can be viewed by users with Item/Extended Read permission or access to the Jenkins controller file system.
oryginał ENCVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:LJenkins Asakusasatellite
APPJenkins≤ 0.1.1
🟢
PATCH DOSTĘPNY
Aktualizacja od producenta gotowa. Wdrożenie w ramach standardowego cyklu.
Tagi
CI/CD
CWE
Powiązane podatności
CVE-2025-31728MEDIUM5.5ten sam produkt
Jenkins AsakusaSatellite Plugin 0.1.1 and earlier does not mask AsakusaSatellite API keys displayed on the job...
CVE-2024-23897CRITICAL9.8⚠ KEVPL ✓ten sam vendor
Jenkins CLI – odczyt dowolnych plików przez path traversal bez uwierzytelnienia
CVE-2019-1003030CRITICAL9.9⚠ KEVPL ✓ten sam vendor
Jenkins Pipeline Groovy Plugin — bypass sandbox i wykonanie kodu (RCE)
CVE-2019-1003029CRITICAL9.9⚠ KEVPL ✓ten sam vendor
Jenkins Script Security Plugin — sandbox bypass umożliwiający RCE
CVE-2018-1000861CRITICAL9.8⚠ KEVPL ✓ten sam vendor
RCE w Jenkins — nieuprawnione wywołanie metod przez Stapler framework