CVE-2017-1000242
published 2017-11-01CVE-2017-1000242: Jenkins Git Client Plugin 2.4.2 and earlier creates temporary file with insecure permissions resulting in information disclosure
PriorityP49low3.3CVSS 3.0
AVLACLPRLUINSUCLINAN
EPSS
0.38%
30.1th percentile
Jenkins Git Client Plugin 2.4.2 and earlier creates temporary file with insecure permissions resulting in information disclosure
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| jenkins | git_client | <= 2.4.2 | — |
| jenkins | git_client_plugin | — | — |
CVSS provenance
nvdv3.03.3LOWCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
vendor_redhat3.3LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Insecure temporary file usage in Jenkins Git Client Plugin
ghsa·2022-05-17
CVE-2017-1000242 [LOW] CWE-200 Insecure temporary file usage in Jenkins Git Client Plugin
Insecure temporary file usage in Jenkins Git Client Plugin
Jenkins Git Client Plugin 2.4.2 and earlier creates temporary file with insecure permissions resulting in information disclosure
OSV
Insecure temporary file usage in Jenkins Git Client Plugin
osv·2022-05-17
CVE-2017-1000242 [LOW] Insecure temporary file usage in Jenkins Git Client Plugin
Insecure temporary file usage in Jenkins Git Client Plugin
Jenkins Git Client Plugin 2.4.2 and earlier creates temporary file with insecure permissions resulting in information disclosure
Red Hat
jenkins-plugin-git-client: Storing sensitive information in world-readable temporary files (SECURITY-445)
vendor_redhat·2017-04-27·CVSS 3.3
CVE-2017-1000242 [LOW] CWE-377 jenkins-plugin-git-client: Storing sensitive information in world-readable temporary files (SECURITY-445)
jenkins-plugin-git-client: Storing sensitive information in world-readable temporary files (SECURITY-445)
Jenkins Git Client Plugin 2.4.2 and earlier creates temporary file with insecure permissions resulting in information disclosure
Package: jenkins-plugin-git-client (Red Hat OpenShift Enterprise 3) - Affected
Jenkins
Jenkins Security Advisory 2017-04-27
vendor_jenkins·2017-04-27·CVSS 3.3
CVE-2017-1000242 [LOW] Jenkins Security Advisory 2017-04-27
Title: Jenkins Security Advisory 2017-04-27
Jenkins Security Advisory 2017-04-27
This advisory announces a vulnerability in the Git Client Plugin .
Description
Git Client Plugin stored sensitive information in world-readable temporary files
SECURITY-445 / CVE-2017-1000242
Temporary files were previously written to the Java temporary directory with default permissions.
A malicious actor with local file access could have captured sensitive information by reading files from that directory.
The temporary files typically are only on the file system for the duration of a single command line git invocation, but cloning a large Git repo could require an extended time with those sensitive files in the temporary directory.
This change sets pe
No detection rules found.
No public exploits indexed.
2017-11-01
Published