Lucene search

K
osvGoogleOSV:CVE-2022-28135
HistoryMar 29, 2022 - 1:15 p.m.

CVE-2022-28135

2022-03-2913:15:08
Google
osv.dev
4
jenkins
instant-messaging
passwords
unencrypted
global configuration
plugins
file system
security vulnerability

AI Score

6.7

Confidence

High

EPSS

0.001

Percentile

28.4%

Jenkins instant-messaging Plugin 1.41 and earlier stores passwords for group chats unencrypted in the global configuration file of plugins based on Jenkins instant-messaging Plugin on the Jenkins controller where they can be viewed by users with access to the Jenkins controller file system.

AI Score

6.7

Confidence

High

EPSS

0.001

Percentile

28.4%

Related for OSV:CVE-2022-28135