First published: Wed Nov 01 2017(Updated: )
Jenkins Git Client Plugin 2.4.2 and earlier creates temporary file with insecure permissions resulting in information disclosure
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Jenkins Git | <=2.4.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-1000242 is classified as medium severity due to the information disclosure risk from insecure temporary file permissions.
To fix CVE-2017-1000242, upgrade the Jenkins Git Client Plugin to version 2.4.3 or later.
CVE-2017-1000242 affects Jenkins Git Client Plugin versions 2.4.2 and earlier.
CVE-2017-1000242 is an information disclosure vulnerability resulting from insecure file permissions.
CVE-2017-1000242 requires access to the Jenkins instance, making it exploitable by authenticated users.