An exposure of sensitive information vulnerability exists in Jenkins Anchore Container Image Scanner Plugin 10.16 and previous versions in AnchoreBuilder.java that allows attackers with Item/ExtendedRead permission or file system access to the Jenkins master to obtain the password stored in this plugin's configuration.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
anchore container image scanner |