CVE-2022-27216: Medium severity jenkins vulnerability
Jenkins dbCharts Plugin 0.5.2 and earlier stores JDBC connection passwords unencrypted in its global configuration file hudson.plugins.dbcharts.DbChartPublisher.xml on the Jenkins controller as part of its configuration.
These passwords can be viewed by users with access to the Jenkins controller file system.
Other sources
Jenkins dbCharts Plugin 0.5.2 and earlier stores JDBC connection passwords unencrypted in its global configuration file on the Jenkins controller where they can be viewed by users with access to the Jenkins controller file system.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-27216?
CVE-2022-27216 is classified as a medium severity vulnerability due to the exposure of sensitive information.
How do I fix CVE-2022-27216?
To fix CVE-2022-27216, upgrade the Jenkins dbCharts Plugin to version 0.5.3 or later.
What types of passwords are affected by CVE-2022-27216?
CVE-2022-27216 affects JDBC connection passwords that are stored unencrypted in the configuration file.
Who is affected by CVE-2022-27216?
Users with access to the Jenkins controller may view the unencrypted passwords affected by CVE-2022-27216.
What is the impact of CVE-2022-27216?
The impact of CVE-2022-27216 includes potential unauthorized access to databases due to exposed JDBC passwords.