First published: Thu Jun 30 2022(Updated: )
Jenkins Build Notifications Plugin 1.5.0 and earlier transmits tokens in plain text as part of the global Jenkins configuration form, potentially resulting in their exposure.
Credit: jenkinsci-cert@googlegroups.com jenkinsci-cert@googlegroups.com jenkinsci-cert@googlegroups.com
Affected Software | Affected Version | How to fix |
---|---|---|
Jenkins Build Notifications | <=1.5.0 | |
maven/tools.devnull:build-notifications | <=1.5.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for Jenkins Build Notifications Plugin is CVE-2022-34801.
The severity level of CVE-2022-34801 is medium (4.3).
CVE-2022-34801 refers to the vulnerability where Jenkins Build Notifications Plugin 1.5.0 and earlier transmits tokens in plain text as part of the global Jenkins configuration form, potentially resulting in their exposure.
Jenkins Build Notifications Plugin versions up to and including 1.5.0 are affected by CVE-2022-34801.
To fix the vulnerability in Jenkins Build Notifications Plugin, update to a version later than 1.5.0.