Loading HuntDB...

GHSA-wj5c-j656-h5fw

GitHub Security Advisory

Exposure of Sensitive Information to an Unauthorized Actor in Jenkins

✓ GitHub Reviewed MODERATE Has CVE

Advisory Details

In Jenkins before versions 2.44 and 2.32.2, node monitor data could be viewed by low privilege users via the remote API. These included system configuration and runtime information of these nodes (SECURITY-343).

Affected Packages

Maven org.jenkins-ci.main:jenkins-core
Affected versions: 0 (fixed in 2.32.2)
Maven org.jenkins-ci.main:jenkins-core
Affected versions: 2.34 (fixed in 2.44)

Related CVEs

Key Information

GHSA ID
GHSA-wj5c-j656-h5fw
Published
May 13, 2022 1:36 AM
Last Modified
July 1, 2022 6:01 PM
CVSS Score
5.0 /10
Primary Ecosystem
Maven
Primary Package
org.jenkins-ci.main:jenkins-core
GitHub Reviewed
✓ Yes

Dataset

Last updated: July 28, 2025 6:37 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.