Lucene search

K
cvelistJenkinsCVELIST:CVE-2022-27206
HistoryMar 15, 2022 - 4:45 p.m.

CVE-2022-27206

2022-03-1516:45:53
jenkins
www.cve.org

7.1 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

28.4%

Jenkins GitLab Authentication Plugin 1.13 and earlier stores the GitLab client secret unencrypted in the global config.xml file on the Jenkins controller where it can be viewed by users with access to the Jenkins controller file system.

CNA Affected

[
  {
    "product": "Jenkins GitLab Authentication Plugin",
    "vendor": "Jenkins project",
    "versions": [
      {
        "lessThanOrEqual": "1.13",
        "status": "affected",
        "version": "unspecified",
        "versionType": "custom"
      },
      {
        "lessThan": "unspecified",
        "status": "unknown",
        "version": "next of 1.13",
        "versionType": "custom"
      }
    ]
  }
]

7.1 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

28.4%

Related for CVELIST:CVE-2022-27206