PT-2022-4019 · Jenkins · Jenkins Http Request Plugin+1

Published

2022-07-27

·

Updated

2023-11-02

·

CVE-2022-36901

CVSS v2.0

6.8

Medium

VectorAV:N/AC:L/Au:S/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions Jenkins HTTP Request Plugin versions 1.15 and earlier
Description The issue is related to the storage of HTTP Request passwords in an unencrypted form in the global configuration file on the Jenkins controller. This allows users with access to the Jenkins controller file system to view these passwords. The vulnerability can be exploited by a remote attacker to disclose protected information.
Recommendations For Jenkins HTTP Request Plugin versions 1.15 and earlier, consider updating to a version that stores passwords securely. As a temporary workaround, restrict access to the Jenkins controller file system to minimize the risk of password disclosure. Avoid using the deprecated Basic/Digest Authentication method until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Insufficiently Protected Credentials

Exposure of Resource to Wrong Sphere

Weakness Enumeration

Related Identifiers

BDU:2022-04852
CVE-2022-36901
GHSA-2QH6-HHVV-M2WW

Affected Products

Jenkins
Jenkins Http Request Plugin