Lucene search

K
osvGoogleOSV:CVE-2022-29052
HistoryApr 12, 2022 - 8:15 p.m.

CVE-2022-29052

2022-04-1220:15:09
Google
osv.dev
9
jenkins
google compute engine
private keys
unencrypted
config.xml
security vulnerability

AI Score

4.5

Confidence

High

EPSS

0.001

Percentile

22.0%

Jenkins Google Compute Engine Plugin 4.3.8 and earlier stores private keys unencrypted in cloud agent config.xml files on the Jenkins controller where they can be viewed by users with Extended Read permission, or access to the Jenkins controller file system.

AI Score

4.5

Confidence

High

EPSS

0.001

Percentile

22.0%