CVE-2019-10433 – io.jenkins.plugins:dingding-notifications
Package
Manager: maven
Name: io.jenkins.plugins:dingding-notifications
Vulnerable Version: >=0 <2.0.0
Severity
Level: Low
CVSS v3.1: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
CVSS v4.0: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
EPSS: 0.0002 pctl0.03744
Details
DingTalk Plugin stores credentials in plain text Jenkins Dingding notifications Plugin stores credentials unencrypted in job config.xml files on the Jenkins master where they can be viewed by users with Extended Read permission, or access to the master file system.
Metadata
Created: 2022-05-24T16:57:28Z
Modified: 2023-12-14T18:09:56Z
Source: https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-xg8p-cp7f-cphx/GHSA-xg8p-cp7f-cphx.json
CWE IDs: ["CWE-256", "CWE-312"]
Alternative ID: GHSA-xg8p-cp7f-cphx
Finding: F020
Auto approve: 1