CVE-2022-41248

Missing Password Field Masking in maven/org.jenkins-ci.plugins/bigpanda-jenkins

Identifiers

GHSA-cpm5-cqr9-7p79, CVE-2022-41248

Package Slug

maven/org.jenkins-ci.plugins/bigpanda-jenkins

Vulnerability

Missing Password Field Masking

Description

Jenkins BigPanda Notifier Plugin 1.4.0 and earlier does not mask the BigPanda API key on the global configuration form, increasing the potential for attackers to observe and capture it.

Affected Versions

All versions up to 1.4.0

Solution

Unfortunately, there is no solution available yet.

Last Modified

2022-09-27

source