CVE-2022-34807
Description
Jenkins Elasticsearch Query Plugin 1.2 and earlier stores a password unencrypted in its global configuration file on the Jenkins controller where it can be viewed by users with access to the Jenkins controller file system.
CWE
- (none)
Affected
- Jenkins project / Jenkins Elasticsearch Query Plugin — v=unspecified ≤1.2 [affected]; v=next of 1.2 <unspecified [unknown]
CVSS
- (none)
References
- https://www.jenkins.io/security/advisory/2022-06-30/#SECURITY-2073 x_refsource_CONFIRM
Source
cvelistV5-main/cves/2022/34xxx/CVE-2022-34807.json