ZDI-CAN-8833: Jenkins dingding-notifications Cleartext Storage of Credentials Information Disclosure Vulnerability
This vulnerability allows local attackers to disclose sensitive information on affected installations of Jenkins. Authentication is required to exploit this vulnerability. The specific flaw exists within the dingding-notifications plugin. The issue results from storing credentials in plaintext. An attacker can leverage this vulnerability to execute code in the context of the build process.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-8833?
The severity of ZDI-CAN-8833 is considered high due to the potential for sensitive information disclosure.
How do I fix ZDI-CAN-8833?
To fix ZDI-CAN-8833, upgrade the dingding-notifications plugin to the latest version as recommended in the security advisory.
Who is affected by ZDI-CAN-8833?
ZDI-CAN-8833 affects installations of Jenkins that use the dingding-notifications plugin.
Can ZDI-CAN-8833 be exploited remotely?
No, ZDI-CAN-8833 requires local access to the Jenkins installation to exploit.
What information can be disclosed due to ZDI-CAN-8833?
ZDI-CAN-8833 can lead to the disclosure of sensitive credentials stored in the dingding-notifications plugin.