PT-2022-26904 · Jenkins · Jenkins Katalon Plugin+2

Published

2022-10-19

·

Updated

2025-05-08

·

CVE-2022-43419

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Jenkins Katalon Plugin versions 1.0.32 and earlier
Description The issue concerns the storage of API keys in an unencrypted manner within job config.xml files on the Jenkins controller. These keys can be accessed by users with Extended Read permission or those who have access to the Jenkins controller file system. The problem arises from the direct storage of API keys as part of the plugin's configuration.
Recommendations For Jenkins Katalon Plugin versions 1.0.32 and earlier, update to version 1.0.33 or later, which no longer stores API keys directly and instead uses the Credentials Plugin integration to access them, once the affected job configurations are saved again.

Fix

Insufficiently Protected Credentials

Weakness Enumeration

Related Identifiers

CVE-2022-43419
GHSA-35RX-7PC8-6963

Affected Products

Credentials Plugin
Jenkins
Jenkins Katalon Plugin