Ecosyste.ms: Advisories

An open API service providing security vulnerability metadata for many open source software ecosystems.

Security Advisories: GSA_kwCzR0hTQS0yM2g5LW01NW0tYzVqcM33tA

Jenkins Token Macro Plugin's recursive token expansion results in information disclosure and DoS

Jenkins Token Macro Plugin recursively applied token expansion.

This could be used by users able to affect input to token expansion (such as change log messages), to inject additional tokens into the input, which would then be expanded, resulting in information disclosure (for example values of environment variables), or denial of service.

Most tokens have been changed to no longer recursively apply token expansion.

Permalink: https://github.com/advisories/GHSA-23h9-m55m-c5jp
JSON: https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS0yM2g5LW01NW0tYzVqcM33tA
Source: GitHub Advisory Database
Origin: Unspecified
Severity: Moderate
Classification: General
Published: almost 2 years ago
Updated: 4 months ago


CVSS Score: 6.5
CVSS vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Identifiers: GHSA-23h9-m55m-c5jp, CVE-2019-1003011
References: Repository: https://github.com/jenkinsci/token-macro-plugin
Blast Radius: 1.0

Affected Packages

maven:org.jenkins-ci.plugins:token-macro
Affected Version Ranges: <= 2.5
Fixed in: 2.6