CVE-2018-1000196

CVE-2018-1000196

A exposure of sensitive information vulnerability exists in Jenkins Gitlab Hook Plugin 1.4.2 and older in gitlab_notifier.rb, views/gitlab_notifier/global.erb that allows attackers with local Jenkins master file system access or control of a Jenkins administrator’s web browser (e.g. malicious extension) to retrieve the configured Gitlab token.

Source: CVE-2018-1000196

답글 남기기

이메일 주소는 공개되지 않습니다. 필수 필드는 *로 표시됩니다