CVE-2022-28135
EUVD-2022-144429.03.2022, 13:15
Jenkins instant-messaging Plugin 1.41 and earlier stores passwords for group chats unencrypted in the global configuration file of plugins based on Jenkins instant-messaging Plugin on the Jenkins controller where they can be viewed by users with access to the Jenkins controller file system.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| jenkins | instant-messaging | 𝑥 < 1.42 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration