Jenkins Telegram Bot Plugin 1.4.0 and earlier stores the Telegram Bot token unencrypted in its global configuration file on the Jenkins controller where it can be viewed by users with access to the Jenkins controller file system.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: jenkins
Published: 2024-05-02T13:28:05.238Z
Updated: 2024-08-02T02:51:09.825Z
Reserved: 2024-04-30T20:53:08.612Z
Link: CVE-2024-34147
Vulnrichment
Updated: 2024-08-02T02:51:09.825Z
NVD
Status : Awaiting Analysis
Published: 2024-05-02T14:15:10.447
Modified: 2024-11-21T09:18:11.790
Link: CVE-2024-34147
Redhat
No data.