PT-2022-18833 · Jenkins · Jenkins Instant-Messaging Plugin+1
S0Nnguy3N
+1
·
Published
2022-03-29
·
Updated
2023-12-21
·
CVE-2022-28135
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Jenkins instant-messaging Plugin versions 1.41 and earlier
Description
The issue allows passwords for group chats to be stored unencrypted in the global configuration file of plugins based on Jenkins instant-messaging Plugin on the Jenkins controller. These passwords can be viewed by users with access to the Jenkins controller file system.
Recommendations
For versions 1.41 and earlier, update to a version that fixes the issue to prevent unencrypted storage of group chat passwords. As a temporary workaround, consider restricting access to the Jenkins controller file system to minimize the risk of password exposure.
Fix
Insufficiently Protected Credentials
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Jenkins
Jenkins Instant-Messaging Plugin