CVE-2023-50772
13.12.2023, 18:15
Jenkins Dingding JSON Pusher Plugin 2.0 and earlier stores access tokens unencrypted in job config.xml files on the Jenkins controller where they can be viewed by users with Item/Extended Read permission or access to the Jenkins controller file system.Enginsight
Vendor | Product | Version |
---|---|---|
jenkins | dingding_json_pusher | 𝑥 ≤ 2.0 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration