First published: Tue May 16 2023(Updated: )
Jenkins Ansible Plugin 204.v8191fd551eb_f and earlier stores extra variables unencrypted in job config.xml files on the Jenkins controller where they can be viewed by users with Item/Extended Read permission or access to the Jenkins controller file system.
Credit: jenkinsci-cert@googlegroups.com jenkinsci-cert@googlegroups.com
Affected Software | Affected Version | How to fix |
---|---|---|
maven/org.jenkins-ci.plugins:ansible | <205.v4cb | 205.v4cb |
<=204.v8191fd551eb_f | ||
Jenkins Ansible | <=204.v8191fd551eb_f |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.