Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Jervis has AES CBC Mode Without Authentication
Vulnerability Description
Jervis is a library for Job DSL plugin scripts and shared Jenkins pipeline libraries. Prior to 2.2, AES/CBC/PKCS5Padding lacks authentication, making it vulnerable to padding oracle attacks and ciphertext manipulation. This vulnerability is fixed in 2.2.
CVSS Information
N/A
Vulnerability Type
认证机制不恰当
Vulnerability Title
Jervis 加密问题漏洞
Vulnerability Description
Jervis是Sam Gleske个人开发者的一个自动化工具。 Jervis 2.2之前版本存在加密问题漏洞,该漏洞源于AES/CBC/PKCS5Padding缺乏身份验证,容易受到填充预言攻击和密文操纵。
CVSS Information
N/A
Vulnerability Type
N/A