cbcvebase.
CVE-2022-45392
published 2022-11-15

CVE-2022-45392: Jenkins NS-ND Integration Performance Publisher Plugin 4.8.0.143 and earlier stores passwords unencrypted in job config.xml files on the Jenkins controller…

medium6.5CVSS 3.1
AVNACLPRLUINSUCHINAN
Jenkins NS-ND Integration Performance Publisher Plugin 4.8.0.143 and earlier stores passwords unencrypted in job config.xml files on the Jenkins controller where they can be viewed by attackers with Extended Read permission, or access to the Jenkins controller file system.

Affected

22 ranges
VendorProductVersion rangeFixed in
jenkinsassociated_files_plugin
jenkinsbart_plugin
jenkinscccc_plugin
jenkinscluster_statistics_plugin
jenkinsconfig_rotator_plugin
jenkinsdelete_log_plugin
jenkinsjapex_plugin
jenkinsjunit_plugin
jenkinsnaginator_plugin
jenkinsns-nd_integration_performance_publisher< 4.8.0.1464.8.0.146
jenkinsns-nd_integration_performance_publisher_plugin
jenkinspipeline_utility_steps_plugin
jenkinsregistry_notification_plugin
jenkinsreverse_proxy_auth_plugin
jenkinsscript_security_plugin
jenkinssourcemonitor_plugin
jenkinssupport_core_plugin
jenkinsurls_in_the_plugin
jenkinsviolations_plugin
jenkinsxml_linter_plugin
jenkinsxp-dev_plugin
jenkins_projectjenkins_ns-nd_integration_performance_publisher_pluginunspecified – 4.8.0.143