logo

CVE-2019-16572 org.jenkins-ci.plugins:weibo

Package

Manager: maven
Name: org.jenkins-ci.plugins:weibo
Vulnerable Version: >=0 <=1.0.1

Severity

Level: Low

CVSS v3.1: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

CVSS v4.0: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N

EPSS: 0.00015 pctl0.02144

Details

Jenkins Weibo Plugin stores credentials unencrypted in its global configuration file Jenkins Weibo Plugin 1.0.1 and earlier stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with access to the master file system.

Metadata

Created: 2022-05-24T17:03:49Z
Modified: 2022-12-06T21:47:50Z
Source: https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-5c97-gxr3-r368/GHSA-5c97-gxr3-r368.json
CWE IDs: ["CWE-1024", "CWE-256", "CWE-522"]
Alternative ID: GHSA-5c97-gxr3-r368
Finding: F085
Auto approve: 1