Lucene search

K
cvelistJenkinsCVELIST:CVE-2022-36901
HistoryJul 27, 2022 - 2:25 p.m.

CVE-2022-36901

2022-07-2714:25:00
jenkins
www.cve.org
9
jenkins
http request
unencrypted passwords
global configuration
file system
access

AI Score

6.9

Confidence

High

EPSS

0.001

Percentile

28.4%

Jenkins HTTP Request Plugin 1.15 and earlier stores HTTP Request passwords unencrypted in its global configuration file on the Jenkins controller where they can be viewed by users with access to the Jenkins controller file system.

CNA Affected

[
  {
    "product": "Jenkins HTTP Request Plugin",
    "vendor": "Jenkins project",
    "versions": [
      {
        "lessThanOrEqual": "1.15",
        "status": "affected",
        "version": "unspecified",
        "versionType": "custom"
      },
      {
        "lessThan": "unspecified",
        "status": "unknown",
        "version": "next of 1.15",
        "versionType": "custom"
      }
    ]
  }
]

AI Score

6.9

Confidence

High

EPSS

0.001

Percentile

28.4%

Related for CVELIST:CVE-2022-36901