SCA: security update for org.jenkins-ci.plugins:config-file-provider (GHSA-6h72-m3xw-fp3c)

medium Tenable Self-Hosted Container Security Plugin ID 433429

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- The Config File Provider Plugin is used to centrally manage configuration files that often include
secrets, such as passwords. Users with only Overall/Read access to Jenkins were able to access URLs
directly that allowed viewing these files. Access to view these files now requires sufficient permissions
to configure the provided files, view the configuration of the folder in which the configuration files are
defined, or have Job/Configure permissions to a job able to use these files. (CVE-2017-1000104)

See Also

https://github.com/advisories/GHSA-6h72-m3xw-fp3c

Plugin Details

Severity: Medium

ID: 433429

Version: Revision 1.2

Type: Local

Family: SCA Checks

Published: 8/19/2025

Updated: 7/2/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Low

Score: 3

Percentile: 23.18

Vendor

Vendor Severity: Medium

CVSS v2

Risk Factor: Medium

Base Score: 4

Temporal Score: 3

Vector: CVSS2#AV:N/AC:L/Au:S/C:P/I:N/A:N

CVSS Score Source: CVE-2017-1000104

CVSS v3

Risk Factor: Medium

Base Score: 6.5

Temporal Score: 5.7

Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 5/13/2022

Vulnerability Publication Date: 8/7/2017

Reference Information

CVE: CVE-2017-1000104

BID: 100324

cwe: CWE-269