PT-2022-17127 · Jenkins · Jenkins Support Core Plugin+1
James Nord
·
Published
2022-02-15
·
Updated
2023-11-30
·
CVE-2022-25187
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Jenkins Support Core Plugin versions 2.79 and earlier
Description
The issue concerns the Jenkins Support Core Plugin, which does not properly redact some sensitive information in the support bundle. This could potentially expose sensitive data. Support Core Plugin 2.79.1 adds a list of keywords whose associated values are redacted, indicating an improvement in handling sensitive information.
Recommendations
For Jenkins Support Core Plugin versions 2.79 and earlier, update to version 2.79.1 or later to ensure that sensitive information is properly redacted in the support bundle.
Fix
Insufficiently Protected Credentials
Cleartext Storage of Sensitive Information
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Jenkins
Jenkins Support Core Plugin