CVE-2022-34199: Medium severity jenkins convertigo mobile platform vulnerability
Jenkins Convertigo Mobile Platform Plugin 1.1 and earlier stores passwords unencrypted in job config.xml files on the Jenkins controller where they can be viewed by users with Extended Read permission, or access to the Jenkins controller file system.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-34199?
CVE-2022-34199 has a medium severity rating due to the potential exposure of unencrypted passwords.
How do I fix CVE-2022-34199?
To fix CVE-2022-34199, upgrade the Jenkins Convertigo Mobile Platform Plugin to version 1.2 or later.
Who is affected by CVE-2022-34199?
CVE-2022-34199 affects users of Jenkins with the Convertigo Mobile Platform Plugin version 1.1 and earlier.
What information is exposed in CVE-2022-34199?
CVE-2022-34199 exposes passwords stored unencrypted in job config.xml files on the Jenkins controller.
What permissions are required to exploit CVE-2022-34199?
Users with Extended Read permission or access to the Jenkins controller file system can exploit CVE-2022-34199.