CVE-2013-6372 Information
Feb 14, 2021
cve
Description
The Subversion plugin before 1.54 for Jenkins stores credentials using base64 encoding which allows local users to obtain passwords and SSH private keys by reading a subversion.credentials file.
Reference
https://bugzilla.redhat.com/show_bug.cgi?id=1032391 https://github.com/jenkinsci/subversion-plugin/commit/7d4562d6f7e40de04bbe29577b51c79f07d05ba6 https://wiki.jenkins-ci.org/display/SECURITY/Jenkins+Security+Advisory+2013-11-20
Share on: