Information Exposure Affecting org.jenkins-ci.main:jenkins-core package, versions [2.335,2.356)
Threat Intelligence
EPSS
0.15% (52nd
percentile)
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID SNYK-JAVA-ORGJENKINSCIMAIN-3157939
- published 6 Dec 2022
- disclosed 24 Jun 2022
- credit Wadeck Follonier, Daniel Beck
How to fix?
Upgrade org.jenkins-ci.main:jenkins-core
to version 2.356 or higher.
Overview
org.jenkins-ci.main:jenkins-core is an open source automation server.
Affected versions of this package are vulnerable to Information Exposure due to bypassable permission checks implicated in CVE-2019-10354.
References
CVSS Scores
version 3.1