Unencrypted JDBC Passwords Vulnerability in Jenkins dbCharts Plugin
CVE-2022-27216
6.5MEDIUM
Key Information:
- Vendor
Jenkins
- Status
- Vendor
- CVE Published:
- 15 March 2022
What is CVE-2022-27216?
The Jenkins dbCharts Plugin prior to version 0.5.3 has a significant security flaw where JDBC connection passwords are stored in an unencrypted format within the global configuration file of the Jenkins controller. This configuration file can be accessed by any user with file system permissions to the Jenkins controller, leading to potential unauthorized access to sensitive database credentials. It is crucial for Jenkins administrators to upgrade to at least version 0.5.3 to mitigate the risk associated with this vulnerability and protect sensitive data from exposure.
Affected Version(s)
Jenkins dbCharts Plugin <= 0.5.2