Home
HIGH: 8.2 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N < 2.2
affected
Description
Jervis is a library for Job DSL plugin scripts and shared Jenkins pipeline libraries. Prior to 2.2, Jervis uses java.util.Random() which is not cryptographically secure for timing attack mitigation. This vulnerability is fixed in 2.2.
Problem types
CWE-330: Use of Insufficiently Random Values
Product status
References
github.com/...jervis/security/advisories/GHSA-c9q6-g3hr-8gww
github.com/...ommit/c3981ff71de7b0f767dfe7b37a2372cb2a51974a