PT-2022-26910 · Jenkins · Jenkins S3 Explorer Plugin+1

Bram Mertens

·

Published

2022-10-19

·

Updated

2025-05-08

·

CVE-2022-43426

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Jenkins S3 Explorer Plugin versions 1.0.8 and earlier
Description The issue concerns the Jenkins S3 Explorer Plugin, where the AWS SECRET ACCESS KEY form field is not masked, increasing the potential for attackers to observe and capture it. This secret is stored encrypted on disk in the s3explorer.xml file on the Jenkins controller as part of its configuration. However, in versions 1.0.8 and earlier, the global configuration form does not mask the AWS SECRET ACCESS KEY form field.
Recommendations For Jenkins S3 Explorer Plugin versions 1.0.8 and earlier, consider disabling the plugin until a patch is available to prevent potential attackers from observing and capturing the AWS SECRET ACCESS KEY. Restrict access to the global configuration form to minimize the risk of exploitation. Avoid using the AWS SECRET ACCESS KEY form field in the affected plugin until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Weakness Enumeration

Related Identifiers

CVE-2022-43426
GHSA-MF4P-WJRM-CMJP

Affected Products

Jenkins
Jenkins S3 Explorer Plugin