PT-2017-10818 · Datadog+1 · Datadog Plugin+1

Alvin Huang

·

Publicado

2017-10-04

·

Atualizado

2022-05-17

·

CVE-2017-1000114

CVSS v2.0

4.3

Média

VetorAV:N/AC:M/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Datadog Plugin (affected versions not specified)
Description The issue concerns the transmission of an API key in plain text as part of the configuration form, potentially exposing it through browser extensions or cross-site scripting vulnerabilities. The API key is used to access the Datadog service and is stored encrypted on disk.
Recommendations For the Datadog Plugin, update to a version that encrypts the API key transmitted to administrators viewing the global configuration form to prevent potential exposure.

Correção

Information Disclosure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2017-1000114
GHSA-HF7W-F4H4-9XP8

Produtos afetados

Datadog Plugin
Jenkins