6.5 MEDIUM
- CVSS version: 3.1
- Attack vector (AV): NETWORK
- Attack complexity (AC): LOW
- Privileges required (PR): LOW
- User interaction (UI): NONE
- Scope (S): UNCHANGED
- Confidentiality impact (C): HIGH
- Integrity impact (I): NONE
- Availability impact (A): NONE
Activity log
- Created suggestion
Jenkins-image: sensitive data disclosure when using openshift jenkins image
A vulnerability was found in Red Hat OpenShift Jenkins. The bearer token is not obfuscated in the logs and potentially carries a high risk if those logs are centralized when collected. The token is typically valid for one year. This flaw allows a malicious user to jeopardize the environment if they have access to sensitive information.
References
Affected products
- <1.1.0.818.v3883b_3b_df89a_
Matching in nixpkgs
pkgs.jenkins
Extendable open source continuous integration server
pkgs.jenkins-job-builder
Jenkins Job Builder is a system for configuring Jenkins jobs using simple YAML files stored in Git
pkgs.emacsPackages.jenkins
None
-
nixos-unstable 20200524.2016
- nixpkgs-unstable 20200524.2016
- nixos-unstable-small 20200524.2016
pkgs.emacsPackages.jenkins-watch
None
-
nixos-unstable 20121004.2326
- nixpkgs-unstable 20121004.2326
- nixos-unstable-small 20121004.2326
pkgs.python311Packages.jenkinsapi
Python API for accessing resources on a Jenkins continuous-integration server
pkgs.python312Packages.jenkinsapi
Python API for accessing resources on a Jenkins continuous-integration server
pkgs.python313Packages.jenkinsapi
Python API for accessing resources on a Jenkins continuous-integration server
pkgs.emacsPackages.jenkinsfile-mode
None
-
nixos-unstable 20230525.2006
- nixpkgs-unstable 20230525.2006
- nixos-unstable-small 20230525.2006
pkgs.python311Packages.python-jenkins
Python bindings for the remote Jenkins API
pkgs.python312Packages.python-jenkins
Python bindings for the remote Jenkins API
pkgs.python311Packages.jenkins-job-builder
Jenkins Job Builder is a system for configuring Jenkins jobs using simple YAML files stored in Git
pkgs.python312Packages.jenkins-job-builder
Jenkins Job Builder is a system for configuring Jenkins jobs using simple YAML files stored in Git
Package maintainers
-
@coreyoconnor Corey O'Connor <coreyoconnor@gmail.com>
-
@earldouglas James Earl Douglas <james@earldouglas.com>
-
@NeQuissimus Tim Steinbach <tim@nequissimus.com>
-
@Bot-wxt1221 Bot-wxt1221 <3264117476@qq.com>
-
@invokes-su Souvik Sen <nixpkgs-commits@deshaw.com>
-
@drets Dmytro Rets <dmitryrets@gmail.com>
-
@de11n Elliot Cameron <nixpkgs-commits@deshaw.com>
-
@gador Florian Brandes <florian.brandes@posteo.de>