PT-2022-22068 · Jenkins · Jenkins Convertigo Mobile Platform Plugin+1

Long Nguyen

·

Published

2022-06-22

·

Updated

2023-11-03

·

CVE-2022-34199

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Jenkins Convertigo Mobile Platform Plugin versions 1.1 and earlier
Description The issue allows passwords to be stored unencrypted in job config.xml files on the Jenkins controller. This can be viewed by users with Extended Read permission or those who have access to the Jenkins controller file system.
Recommendations For Jenkins Convertigo Mobile Platform Plugin versions 1.1 and earlier, update to a version that properly encrypts passwords in job config.xml files to prevent unauthorized access. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Insufficiently Protected Credentials

Weakness Enumeration

Related Identifiers

CVE-2022-34199
GHSA-C8MF-MC3F-2WVC

Affected Products

Jenkins
Jenkins Convertigo Mobile Platform Plugin