logo

CVE-2019-10433 io.jenkins.plugins:dingding-notifications

Package

Manager: maven
Name: io.jenkins.plugins:dingding-notifications
Vulnerable Version: >=0 <2.0.0

Severity

Level: Low

CVSS v3.1: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

CVSS v4.0: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N

EPSS: 0.0002 pctl0.03744

Details

DingTalk Plugin stores credentials in plain text Jenkins Dingding notifications Plugin stores credentials unencrypted in job config.xml files on the Jenkins master where they can be viewed by users with Extended Read permission, or access to the master file system.

Metadata

Created: 2022-05-24T16:57:28Z
Modified: 2023-12-14T18:09:56Z
Source: https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-xg8p-cp7f-cphx/GHSA-xg8p-cp7f-cphx.json
CWE IDs: ["CWE-256", "CWE-312"]
Alternative ID: GHSA-xg8p-cp7f-cphx
Finding: F020
Auto approve: 1