CVE-2022-45392

Plaintext Storage of a Password in maven/io.jenkins.plugins/cavisson-ns-nd-integration

Identifiers

GHSA-x2w2-5552-fjv6, CVE-2022-45392

Package Slug

maven/io.jenkins.plugins/cavisson-ns-nd-integration

Vulnerability

Plaintext Storage of a Password

Description

Jenkins NS-ND Integration Performance Publisher Plugin 4.8.0.143 and earlier stores passwords unencrypted in job config.xml files on the Jenkins controller where they can be viewed by attackers with Extended Read permission, or access to the Jenkins controller file system.

Affected Versions

All versions up to 4.8.0.143

Solution

Unfortunately, there is no solution available yet.

Last Modified

2022-11-22

source