Jenkins Parameterized Trigger Plugin 2.43 and earlier captures environment variables passed to builds triggered using Jenkins Parameterized Trigger Plugin, including password parameter values, in their `build.xml` files. These values are stored unencrypted and can be viewed by users with access to the Jenkins controller file system.
Advisories
Source ID Title
EUVD EUVD EUVD-2022-1325 Jenkins Parameterized Trigger Plugin 2.43 and earlier captures environment variables passed to builds triggered using Jenkins Parameterized Trigger Plugin, including password parameter values, in their `build.xml` files. These values are stored unencrypted and can be viewed by users with access to the Jenkins controller file system.
Github GHSA Github GHSA GHSA-5mpf-hw8f-86w9 Sensitive parameter values captured in build metadata files by Jenkins Parameterized Trigger Plugin
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: jenkins

Published:

Updated: 2024-08-03T05:25:31.103Z

Reserved: 2022-03-15T00:00:00

Link: CVE-2022-27195

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2022-03-15T17:15:09.540

Modified: 2024-11-21T06:55:23.227

Link: CVE-2022-27195

cve-icon Redhat

Severity : Low

Publid Date: 2022-03-15T00:00:00Z

Links: CVE-2022-27195 - Bugzilla

cve-icon OpenCVE Enrichment

No data.