Jenkins CONS3RT Plugin 1.0.0 and earlier stores Cons3rt API token unencrypted in job config.xml files on the Jenkins controller where it can be viewed by users with access to the Jenkins controller file system.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: jenkins

Published: 2022-09-21T15:46:12

Updated: 2024-08-03T12:42:44.074Z

Reserved: 2022-09-21T00:00:00

Link: CVE-2022-41255

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2022-09-21T16:15:11.683

Modified: 2023-11-01T20:58:58.857

Link: CVE-2022-41255

cve-icon Redhat

No data.