CVE-2022-34806

Plaintext Storage of a Password in maven/org.jenkins-ci.plugins/jigomerge

Identifiers

GHSA-h5g3-v72x-hc6f, CVE-2022-34806

Package Slug

maven/org.jenkins-ci.plugins/jigomerge

Vulnerability

Plaintext Storage of a Password

Description

Jenkins Jigomerge Plugin 0.9 and earlier stores passwords unencrypted in job config.xml files on the Jenkins controller where they can be viewed by users with Extended Read permission, or access to the Jenkins controller file system.

Affected Versions

All versions up to 0.9

Solution

Unfortunately, there is no solution available yet.

Last Modified

2022-07-26

source