PT-2022-22354 · Jenkins · Jenkins Rocketchat Notifier Plugin+1
Long Nguyen
·
Published
2022-06-30
·
Updated
2023-11-22
·
CVE-2022-34802
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Jenkins RocketChat Notifier Plugin versions 1.5.2 and earlier
Description
The issue concerns the storage of sensitive information in the global configuration file on the Jenkins controller. Specifically, the login password and webhook token are stored unencrypted, allowing users with access to the Jenkins controller file system to view them. The configuration file in question is
RocketChatNotifier.xml.Recommendations
For Jenkins RocketChat Notifier Plugin versions 1.5.2 and earlier, consider restricting access to the Jenkins controller file system to minimize the risk of sensitive information exposure. As a temporary workaround, limit user access to the
RocketChatNotifier.xml file until a secure storage solution is implemented.Fix
Insufficiently Protected Credentials
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Jenkins
Jenkins Rocketchat Notifier Plugin