CVE-2022-34801

LOW3.3EPSS 0.21%

Cleartext Storage of Sensitive Information in Jenkins Build Notifications Plugin

Published: 7/1/2022Modified: 2/16/2024
Also known as:GHSA-7298-w54j-q7wm

Description

Jenkins Build Notifications Plugin 1.5.0 and earlier transmits tokens in plain text as part of the global Jenkins configuration form, potentially resulting in their exposure.

Affected packages (1)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1LOW3.3CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

References (3)