PT-2017-10818 · Datadog+1 · Datadog Plugin+1

Alvin Huang

·

Published

2017-10-04

·

Updated

2022-05-17

·

CVE-2017-1000114

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Datadog Plugin (affected versions not specified)
Description The issue concerns the transmission of an API key in plain text as part of the configuration form, potentially exposing it through browser extensions or cross-site scripting vulnerabilities. The API key is used to access the Datadog service and is stored encrypted on disk.
Recommendations For the Datadog Plugin, update to a version that encrypts the API key transmitted to administrators viewing the global configuration form to prevent potential exposure.

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-1000114
GHSA-HF7W-F4H4-9XP8

Affected Products

Datadog Plugin
Jenkins