CVE-2022-28135

Source
https://nvd.nist.gov/vuln/detail/CVE-2022-28135
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-28135.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2022-28135
Aliases
Published
2022-03-29T13:15:08Z
Modified
2024-09-03T04:14:38.453456Z
Severity
  • 6.5 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N CVSS Calculator
Summary
[none]
Details

Jenkins instant-messaging Plugin 1.41 and earlier stores passwords for group chats unencrypted in the global configuration file of plugins based on Jenkins instant-messaging Plugin on the Jenkins controller where they can be viewed by users with access to the Jenkins controller file system.

References

Affected packages

Git / github.com/jenkinsci/instant-messaging-plugin

Affected ranges

Type
GIT
Repo
https://github.com/jenkinsci/instant-messaging-plugin
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed

Affected versions

instant-messaging-1.*

instant-messaging-1.17
instant-messaging-1.18
instant-messaging-1.19
instant-messaging-1.20
instant-messaging-1.21
instant-messaging-1.22
instant-messaging-1.23
instant-messaging-1.24
instant-messaging-1.25
instant-messaging-1.26
instant-messaging-1.27
instant-messaging-1.28
instant-messaging-1.29
instant-messaging-1.30
instant-messaging-1.31
instant-messaging-1.32
instant-messaging-1.33
instant-messaging-1.34
instant-messaging-1.35
instant-messaging-1.37
instant-messaging-1.38
instant-messaging-1.39
instant-messaging-1.40
instant-messaging-1.41