Information disclosure in Chef Identity - CVE-2023-39155
Published: July 27, 2023
Chef Identity
Jenkins
Description
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to the affected plugin stores the user.pem key in its global configuration file io.chef.jenkins.ChefIdentityBuildWrapper.xml on the Jenkins controller as part of its configuration. A remote attacker can gain unauthorized access to sensitive information on the system.