A missing permission check in Jenkins PAM Authentication Plugin 1.5 and earlier, except 1.4.1 in PamSecurityRealm.DescriptorImpl#doTest allowed users with Overall/Read permission to obtain limited information about the file /etc/shadow and the user Jenkins is running as.
2019-05-21T13:29:00.227
2024-11-21T04:18:53.010
Modified
CVSSv3.1: 4.3 (MEDIUM)
AV:N/AC:L/Au:S/C:P/I:N/A:N
8.0
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | jenkins | pluggable_authentication_module | 1.0 | Yes |
Application | jenkins | pluggable_authentication_module | 1.1 | Yes |
Application | jenkins | pluggable_authentication_module | 1.2 | Yes |
Application | jenkins | pluggable_authentication_module | 1.3 | Yes |
Application | jenkins | pluggable_authentication_module | 1.4 | Yes |
Application | jenkins | pluggable_authentication_module | 1.5 | Yes |