Jenkins BigPanda Notifier Plugin 1.4.0 and earlier does not mask the BigPanda API key on the global configuration form, increasing the potential for attackers to observe and capture it.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-6781 | Jenkins BigPanda Notifier Plugin 1.4.0 and earlier does not mask the BigPanda API key on the global configuration form, increasing the potential for attackers to observe and capture it. |
Github GHSA |
GHSA-cpm5-cqr9-7p79 | Jenkins BigPanda Notifier Plugin Missing Password Field Masking |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Tue, 27 May 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: jenkins
Published:
Updated: 2025-05-27T18:24:55.247Z
Reserved: 2022-09-21T00:00:00.000Z
Link: CVE-2022-41248
Updated: 2024-08-03T12:35:49.595Z
Status : Modified
Published: 2022-09-21T16:15:11.277
Modified: 2025-05-27T19:15:24.107
Link: CVE-2022-41248
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA