Jenkins RocketChat Notifier Plugin 1.5.2 and earlier stores the login password and webhook token unencrypted in its global configuration file on the Jenkins controller where they can be viewed by users with access to the Jenkins controller file system.
References
Link | Resource |
---|---|
https://www.jenkins.io/security/advisory/2022-06-30/#SECURITY-2088 | Vendor Advisory |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: jenkins
Published: 2022-06-30T17:48:14
Updated: 2023-10-24T14:23:33.915Z
Reserved: 2022-06-29T00:00:00
Link: CVE-2022-34802
JSON object: View
NVD Information
Status : Analyzed
Published: 2022-06-30T18:15:13.877
Modified: 2023-11-22T19:59:33.463
Link: CVE-2022-34802
JSON object: View
Redhat Information
No data.
CWE