Unencrypted JDBC Passwords Vulnerability in Jenkins dbCharts Plugin
CVE-2022-27216
What is CVE-2022-27216?
The Jenkins dbCharts Plugin prior to version 0.5.3 has a significant security flaw where JDBC connection passwords are stored in an unencrypted format within the global configuration file of the Jenkins controller. This configuration file can be accessed by any user with file system permissions to the Jenkins controller, leading to potential unauthorized access to sensitive database credentials. It is crucial for Jenkins administrators to upgrade to at least version 0.5.3 to mitigate the risk associated with this vulnerability and protect sensitive data from exposure.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Jenkins dbCharts Plugin <= 0.5.2
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved