PT-2017-10818 · Datadog+1 · Datadog Plugin+1
Alvin Huang
·
Publicado
2017-10-04
·
Atualizado
2022-05-17
·
CVE-2017-1000114
CVSS v2.0
4.3
Média
| Vetor | AV:N/AC:M/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Datadog Plugin (affected versions not specified)
Description
The issue concerns the transmission of an API key in plain text as part of the configuration form, potentially exposing it through browser extensions or cross-site scripting vulnerabilities. The API key is used to access the Datadog service and is stored encrypted on disk.
Recommendations
For the Datadog Plugin, update to a version that encrypts the API key transmitted to administrators viewing the global configuration form to prevent potential exposure.
Correção
Information Disclosure
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Datadog Plugin
Jenkins