Insecure Token Storage in Jenkins Build Notifications Plugin by Jenkins
CVE-2022-34800
4.3MEDIUM
Key Information:
- Vendor
Jenkins
- Vendor
- CVE Published:
- 30 June 2022
What is CVE-2022-34800?
The Jenkins Build Notifications Plugin stores sensitive tokens in an unencrypted format within its global configuration files on the Jenkins controller. This vulnerability allows users with file system access to the Jenkins controller to potentially view these tokens, which may lead to unauthorized actions or information disclosure. Proper security measures should be implemented to safeguard sensitive configuration data from unauthorized access.
Affected Version(s)
Jenkins Build Notifications Plugin <= 1.5.0