Lucene search

K
cvelistJenkinsCVELIST:CVE-2024-34147
HistoryMay 02, 2024 - 1:28 p.m.

CVE-2024-34147

2024-05-0213:28:05
jenkins
www.cve.org
6
jenkins
telegram bot plugin
unencrypted storage
global configuration file
security vulnerability

AI Score

6.6

Confidence

High

EPSS

0

Percentile

9.0%

Jenkins Telegram Bot Plugin 1.4.0 and earlier stores the Telegram Bot token unencrypted in its global configuration file on the Jenkins controller where it can be viewed by users with access to the Jenkins controller file system.

CNA Affected

[
  {
    "vendor": "Jenkins Project",
    "product": "Jenkins Telegram Bot Plugin",
    "versions": [
      {
        "version": "0",
        "versionType": "maven",
        "lessThanOrEqual": "1.4.0",
        "status": "affected"
      }
    ],
    "defaultStatus": "unknown"
  }
]

AI Score

6.6

Confidence

High

EPSS

0

Percentile

9.0%

Related for CVELIST:CVE-2024-34147