PT-2022-14830 · Jenkins · Jenkins Metrics Plugin+1

Wasin Saengow

·

Published

2022-01-12

·

Updated

2023-11-30

·

CVE-2022-20621

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Jenkins Metrics Plugin versions 4.0.2.8 and earlier
Description The issue allows an access key to be stored unencrypted in the global configuration file on the Jenkins controller. This access key can be viewed by users with access to the Jenkins controller file system. The file jenkins.metrics.api.MetricsAccessKey.xml is specifically mentioned as part of the configuration where this access key is stored.
Recommendations For Jenkins Metrics Plugin versions 4.0.2.8 and earlier, consider updating to version 4.0.2.8.1 or later, as it stores the access key encrypted once its configuration is saved again. As a temporary workaround, restrict access to the Jenkins controller file system to minimize the risk of the access key being viewed by unauthorized users.

Fix

Insufficiently Protected Credentials

Weakness Enumeration

Related Identifiers

CVE-2022-20621
GHSA-GG9M-X3CG-69VH

Affected Products

Jenkins
Jenkins Metrics Plugin