CVE-2019-16572 – org.jenkins-ci.plugins:weibo
Package
Manager: maven
Name: org.jenkins-ci.plugins:weibo
Vulnerable Version: >=0 <=1.0.1
Severity
Level: Low
CVSS v3.1: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
CVSS v4.0: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
EPSS: 0.00015 pctl0.02144
Details
Jenkins Weibo Plugin stores credentials unencrypted in its global configuration file Jenkins Weibo Plugin 1.0.1 and earlier stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with access to the master file system.
Metadata
Created: 2022-05-24T17:03:49Z
Modified: 2022-12-06T21:47:50Z
Source: https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-5c97-gxr3-r368/GHSA-5c97-gxr3-r368.json
CWE IDs: ["CWE-1024", "CWE-256", "CWE-522"]
Alternative ID: GHSA-5c97-gxr3-r368
Finding: F085
Auto approve: 1