VDB
Sign up
MEDIUM5.3

GHSA-cw68-xmm4-c83r

Agent-to-controller security bypass in Jenkins Conjur Secrets Plugin allows retrieving all credentials

Quick fix

GHSA-cw68-xmm4-c83r — org.conjur.jenkins:conjur-credentials: upgrade to the fixed version with the command below.

# pom.xml: bump <version>1.0.10</version> for org.conjur.jenkins:conjur-credentials

Details

Jenkins Conjur Secrets Plugin 1.0.9 and earlier implements functionality that allows attackers able to control agent processes to retrieve all username/password credentials stored on the Jenkins controller.

Are you affected?

Enter the version of the package you're using.

Affected packages

Maven/org.conjur.jenkins:conjur-credentials
Introduced in: 0Fixed in: 1.0.10
Fix# pom.xml: bump <version>1.0.10</version> for org.conjur.jenkins:conjur-credentials

References