First published: Wed Sep 20 2023(Updated: )
Jenkins 2.50 through 2.423 (both inclusive), LTS 2.60.1 through 2.414.1 (both inclusive) does not exclude sensitive build variables (e.g., password parameter values) from the search in the build history widget, allowing attackers with Item/Read permission to obtain values of sensitive variables used in builds by iteratively testing different characters until the correct sequence is discovered.
Credit: jenkinsci-cert@googlegroups.com jenkinsci-cert@googlegroups.com jenkinsci-cert@googlegroups.com
Affected Software | Affected Version | How to fix |
---|---|---|
Jenkins Jenkins | >=2.50<2.424 | |
Jenkins Jenkins | >=2.60.1<2.414.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-43494 is a vulnerability in Jenkins that allows sensitive build variables to be included in the build history widget.
CVE-2023-43494 has a severity rating of 4.3 (medium).
Jenkins versions 2.50 through 2.423 (inclusive) and LTS 2.60.1 through 2.414.1 (inclusive) are affected by CVE-2023-43494.
To fix CVE-2023-43494, update Jenkins to version 2.424+ or 2.414.2+ depending on the specific affected version.
More information about CVE-2023-43494 can be found at the following references: [link1], [link2], [link3].