Description
Jenkins Telegram Bot Plugin 1.4.0 and earlier stores the Telegram Bot token unencrypted in its global configuration file on the Jenkins controller where it can be viewed by users with access to the Jenkins controller file system.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-1539 | Jenkins Telegram Bot Plugin 1.4.0 and earlier stores the Telegram Bot token unencrypted in its global configuration file on the Jenkins controller where it can be viewed by users with access to the Jenkins controller file system. |
Github GHSA |
GHSA-94pr-w968-h923 | Jenkins Telegram Bot Plugin stores the Telegram Bot token in plaintext |
References
History
Fri, 10 Oct 2025 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Jenkins telegram Bot
|
|
| CPEs | cpe:2.3:a:jenkins:telegram_bot:*:*:*:*:*:jenkins:*:* | |
| Vendors & Products |
Jenkins telegram Bot
|
Thu, 13 Feb 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Jenkins
Jenkins jenkins-telegram-bot |
|
| CPEs | cpe:2.3:a:jenkins:jenkins-telegram-bot:-:*:*:*:*:*:*:* | |
| Vendors & Products |
Jenkins
Jenkins jenkins-telegram-bot |
|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: jenkins
Published:
Updated: 2025-02-13T17:52:26.471Z
Reserved: 2024-04-30T20:53:08.612Z
Link: CVE-2024-34147
Updated: 2024-08-02T02:51:09.825Z
Status : Analyzed
Published: 2024-05-02T14:15:10.447
Modified: 2025-10-10T15:34:45.500
Link: CVE-2024-34147
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA