First published: Wed Jan 12 2022(Updated: )
Jenkins Publish Over SSH Plugin 1.22 and earlier stores password unencrypted in its global configuration file on the Jenkins controller where it can be viewed by users with access to the Jenkins controller file system.
Credit: jenkinsci-cert@googlegroups.com jenkinsci-cert@googlegroups.com jenkinsci-cert@googlegroups.com
Affected Software | Affected Version | How to fix |
---|---|---|
Jenkins Publish Over Ssh | <=1.22 | |
maven/org.jenkins-ci.plugins:publish-over-ssh | <1.23 | 1.23 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2022-23114 is rated as low with a severity value of 3.3.
Jenkins Publish Over SSH Plugin 1.22 stores passwords unencrypted in its global configuration file on the Jenkins controller.
The passwords stored by Jenkins Publish Over SSH Plugin 1.22 can be viewed by users with access to the Jenkins controller file system.