Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-hpm9-fx8v-w45v

Опубликовано: 30 мар. 2022
Источник: github
Github: Прошло ревью
CVSS3: 6.5

Описание

Plaintext storage in Jenkins instant-messaging Plugin

Jenkins instant-messaging Plugin 1.41 and earlier stores passwords for group chats unencrypted in the global configuration file of plugins based on Jenkins instant-messaging Plugin on the Jenkins controller where they can be viewed by users with access to the Jenkins controller file system.

Пакеты

Наименование

org.jvnet.hudson.plugins:instant-messaging

maven
Затронутые версииВерсия исправления

< 1.42

1.42

EPSS

Процентиль: 62%
0.00435
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-256
CWE-522

Связанные уязвимости

CVSS3: 6.5
nvd
почти 4 года назад

Jenkins instant-messaging Plugin 1.41 and earlier stores passwords for group chats unencrypted in the global configuration file of plugins based on Jenkins instant-messaging Plugin on the Jenkins controller where they can be viewed by users with access to the Jenkins controller file system.

EPSS

Процентиль: 62%
0.00435
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-256
CWE-522