Jenkins OpsGenie Plugin 1.9 and earlier transmits API keys in plain text as part of the global Jenkins configuration form and job configuration forms, potentially resulting in their exposure.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-6285 | Jenkins OpsGenie Plugin 1.9 and earlier transmits API keys in plain text as part of the global Jenkins configuration form and job configuration forms, potentially resulting in their exposure. |
Github GHSA |
GHSA-7r65-pjgv-h2h9 | Jenkins OpsGenie Plugin vulnerable to Cleartext Transmission of Sensitive Information |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Status: PUBLISHED
Assigner: jenkins
Published:
Updated: 2024-08-03T09:22:09.859Z
Reserved: 2022-06-29T00:00:00
Link: CVE-2022-34804
No data.
Status : Modified
Published: 2022-06-30T18:15:14.200
Modified: 2024-11-21T07:10:13.153
Link: CVE-2022-34804
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA