PT-2022-18833 · Jenkins · Jenkins Instant-Messaging Plugin+1

S0Nnguy3N

+1

·

Published

2022-03-29

·

Updated

2023-12-21

·

CVE-2022-28135

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Jenkins instant-messaging Plugin versions 1.41 and earlier
Description The issue allows passwords for group chats to be stored unencrypted in the global configuration file of plugins based on Jenkins instant-messaging Plugin on the Jenkins controller. These passwords can be viewed by users with access to the Jenkins controller file system.
Recommendations For versions 1.41 and earlier, update to a version that fixes the issue to prevent unencrypted storage of group chat passwords. As a temporary workaround, consider restricting access to the Jenkins controller file system to minimize the risk of password exposure.

Fix

Insufficiently Protected Credentials

Weakness Enumeration

Related Identifiers

CVE-2022-28135
GHSA-HPM9-FX8V-W45V

Affected Products

Jenkins
Jenkins Instant-Messaging Plugin