Unencrypted Access Tokens in Jenkins Dingding JSON Pusher Plugin
CVE-2023-50772
4.3MEDIUM
Key Information:
- Vendor
Jenkins
- Vendor
- CVE Published:
- 13 December 2023
What is CVE-2023-50772?
The Dingding JSON Pusher Plugin for Jenkins fails to securely handle access tokens, storing them unencrypted in the job config.xml files located on the Jenkins controller. This oversight allows users with sufficient permissions or file system access to view sensitive tokens, potentially leading to unauthorized access or manipulation of Jenkins jobs. It is crucial for administrators to assess and mitigate the risks associated with this vulnerability to safeguard their Jenkins environment.
Affected Version(s)
Jenkins Dingding JSON Pusher Plugin 0 <= 2.0