First published: Mon Jul 09 2018(Updated: )
Jenkins project Jenkins AWS CodeDeploy Plugin version 1.19 and earlier contains a File and Directory Information Exposure vulnerability in AWSCodeDeployPublisher.java that can result in Disclosure of environment variables. This vulnerability appears to have been fixed in 1.20 and later.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Jenkins Aws Codedeploy | <=1.19 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2018-1000402 is considered low as it results in the exposure of environment variables.
To fix CVE-2018-1000402, upgrade the Jenkins AWS CodeDeploy Plugin to version 1.20 or later.
CVE-2018-1000402 affects Jenkins AWS CodeDeploy Plugin versions 1.19 and earlier.
CVE-2018-1000402 is a File and Directory Information Exposure vulnerability.
CVE-2018-1000402 can result in the disclosure of sensitive environment variables.