Information Exposure Affecting org.jenkins-ci.plugins:zos-connector package, versions [,2.0.0)


Severity

Recommended
0.0
high
0
10

CVSS assessment made by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.1% (43rd percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-JAVA-ORGJENKINSCIPLUGINS-32402
  • published1 Jul 2018
  • disclosed26 Jun 2018
  • creditViktor Gazdag

Introduced: 26 Jun 2018

CVE-2018-1000608  (opens in a new tab)
CWE-200  (opens in a new tab)

How to fix?

Upgrade org.jenkins-ci.plugins:zos-connector to version 2.0.0 or higher.

Overview

org.jenkins-ci.plugins:zos-connector is a Plugin for connection of Jenkins CI to IBM zOS including integration of IBM SCLM as SCM.

Affected versions of this package are vulnerable to Information Exposure via the SCLMSCM.java method. An attacker with local file system access or control of a Jenkins administrators web browser could retrieve the configured password.

CVSS Scores

version 3.1