MEDIUM4.3
GHSA-p3f5-98cv-562j
Jenkins is missing a permission check on password fields
Quick fix
GHSA-p3f5-98cv-562j — org.jenkins-ci.main:jenkins-core: upgrade to the fixed version with the command below.
# pom.xml: bump <version>2.541</version> for org.jenkins-ci.main:jenkins-coreDetails
A missing permission check in Jenkins 2.540 and earlier, LTS 2.528.2 and earlier allows attackers with View/Read permission to view encrypted password values in views.
Are you affected?
Enter the version of the package you're using.
Affected packages
Maven/org.jenkins-ci.main:jenkins-core
Introduced in:
2.529Fixed in: 2.541Fix
# pom.xml: bump <version>2.541</version> for org.jenkins-ci.main:jenkins-coreMaven/org.jenkins-ci.main:jenkins-core
Introduced in:
0Fixed in: 2.528.3Fix
# pom.xml: bump <version>2.528.3</version> for org.jenkins-ci.main:jenkins-core