PT-2022-22354 · Jenkins · Jenkins Rocketchat Notifier Plugin+1

Long Nguyen

·

Published

2022-06-30

·

Updated

2023-11-22

·

CVE-2022-34802

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Jenkins RocketChat Notifier Plugin versions 1.5.2 and earlier
Description The issue concerns the storage of sensitive information in the global configuration file on the Jenkins controller. Specifically, the login password and webhook token are stored unencrypted, allowing users with access to the Jenkins controller file system to view them. The configuration file in question is RocketChatNotifier.xml.
Recommendations For Jenkins RocketChat Notifier Plugin versions 1.5.2 and earlier, consider restricting access to the Jenkins controller file system to minimize the risk of sensitive information exposure. As a temporary workaround, limit user access to the RocketChatNotifier.xml file until a secure storage solution is implemented.

Fix

Insufficiently Protected Credentials

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-34802
GHSA-PGP9-X83G-V8X8

Affected Products

Jenkins
Jenkins Rocketchat Notifier Plugin