CVE-2022-27206

Severity
6.5MEDIUM
EPSS
0.1%
top 76.66%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 15
Latest updateMar 16

Description

Jenkins GitLab Authentication Plugin 1.13 and earlier stores the GitLab client secret unencrypted in the global config.xml file on the Jenkins controller where it can be viewed by users with access to the Jenkins controller file system.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NExploitability: 2.8 | Impact: 3.6

Affected Packages3 packages

🔴Vulnerability Details

3
OSV
Client Secret stored in plain text by Jenkins GitLab Authentication Plugin2022-03-16
GHSA
Client Secret stored in plain text by Jenkins GitLab Authentication Plugin2022-03-16
CVEList
CVE-2022-27206: Jenkins GitLab Authentication Plugin 12022-03-15

📋Vendor Advisories

2
GitLab
CVE-2022-27206: Jenkins GitLab Authentication Plugin 1.13 and earlier stores the GitLab client secret unencrypted in the global config.xml file on the Jenkins control2022-03-15
Jenkins
Jenkins Security Advisory 2022-03-152022-03-15
CVE-2022-27206 (MEDIUM CVSS 6.5) | Jenkins GitLab Authentication Plugi | cvebase.io