Описание
Jenkins instant-messaging Plugin 1.41 and earlier stores passwords for group chats unencrypted in the global configuration file of plugins based on Jenkins instant-messaging Plugin on the Jenkins controller where they can be viewed by users with access to the Jenkins controller file system.
Ссылки
- Mailing ListThird Party Advisory
- Vendor Advisory
- Mailing ListThird Party Advisory
- Vendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 1.42 (исключая)
cpe:2.3:a:jenkins:instant-messaging:*:*:*:*:*:jenkins:*:*
EPSS
Процентиль: 62%
0.00435
Низкий
6.5 Medium
CVSS3
4 Medium
CVSS2
Дефекты
CWE-522
Связанные уязвимости
CVSS3: 6.5
github
почти 4 года назад
Plaintext storage in Jenkins instant-messaging Plugin
EPSS
Процентиль: 62%
0.00435
Низкий
6.5 Medium
CVSS3
4 Medium
CVSS2
Дефекты
CWE-522