Description
Jenkins Parameterized Trigger Plugin 2.43 and earlier captures environment variables passed to builds triggered using Jenkins Parameterized Trigger Plugin, including password parameter values, in their `build.xml` files. These values are stored unencrypted and can be viewed by users with access to the Jenkins controller file system.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-1325 | Jenkins Parameterized Trigger Plugin 2.43 and earlier captures environment variables passed to builds triggered using Jenkins Parameterized Trigger Plugin, including password parameter values, in their `build.xml` files. These values are stored unencrypted and can be viewed by users with access to the Jenkins controller file system. |
Github GHSA |
GHSA-5mpf-hw8f-86w9 | Sensitive parameter values captured in build metadata files by Jenkins Parameterized Trigger Plugin |
References
History
No history.
Status: PUBLISHED
Assigner: jenkins
Published:
Updated: 2024-08-03T05:25:31.103Z
Reserved: 2022-03-15T00:00:00.000Z
Link: CVE-2022-27195
No data.
Status : Modified
Published: 2022-03-15T17:15:09.540
Modified: 2024-11-21T06:55:23.227
Link: CVE-2022-27195
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA