CVE-2022-34799

LOW3.3EPSS 0.34%

Plaintext Storage of a Password in Jenkins Deployment Dashboard Plugin

Published: 7/1/2022Modified: 2/16/2024
Also known as:GHSA-56hc-wf49-2h96

Description

Deployment Dashboard Plugin 1.0.10 and earlier stores a password unencrypted in its global configuration file `de.codecentric.jenkins.dashboard.DashboardView.xml` on the Jenkins controller as part of its configuration. This password can be viewed by users with access to the Jenkins controller file system.

Affected packages (1)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1LOW3.3CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

References (3)