GHSA-23h9-m55m-c5jp
GitHub Security Advisory
Jenkins Token Macro Plugin's recursive token expansion results in information disclosure and DoS
✓ GitHub Reviewed
MODERATE
Has CVE
Advisory Details
Jenkins Token Macro Plugin recursively applied token expansion.
This could be used by users able to affect input to token expansion (such as change log messages), to inject additional tokens into the input, which would then be expanded, resulting in information disclosure (for example values of environment variables), or denial of service.
Most tokens have been changed to no longer recursively apply token expansion.
Affected Packages
Maven
org.jenkins-ci.plugins:token-macro
Affected versions:
0
(fixed in 2.6)
Related CVEs
Key Information
5.0
/10
Dataset
Last updated: August 25, 2025 6:33 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.