PT-2022-17127 · Jenkins · Jenkins Support Core Plugin+1

James Nord

·

Published

2022-02-15

·

Updated

2023-11-30

·

CVE-2022-25187

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Jenkins Support Core Plugin versions 2.79 and earlier
Description The issue concerns the Jenkins Support Core Plugin, which does not properly redact some sensitive information in the support bundle. This could potentially expose sensitive data. Support Core Plugin 2.79.1 adds a list of keywords whose associated values are redacted, indicating an improvement in handling sensitive information.
Recommendations For Jenkins Support Core Plugin versions 2.79 and earlier, update to version 2.79.1 or later to ensure that sensitive information is properly redacted in the support bundle.

Fix

Insufficiently Protected Credentials

Cleartext Storage of Sensitive Information

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-25187
GHSA-5M8F-V3GW-H94W

Affected Products

Jenkins
Jenkins Support Core Plugin