CVE-2022-34199
Published on: Not Yet Published
Last Modified on: 06/23/2022 05:19:00 PM UTC
Certain versions of Jenkins Convertigo Mobile Platform Plugin from Jenkins Project contain the following vulnerability:
Jenkins Convertigo Mobile Platform Plugin 1.1 and earlier stores passwords unencrypted in job config.xml files on the Jenkins controller where they can be viewed by users with Extended Read permission, or access to the Jenkins controller file system.
- CVE-2022-34199 has been assigned by
[email protected] to track the vulnerability
- Affected Vendor/Software:
Jenkins project - Jenkins Convertigo Mobile Platform Plugin version <= 1.1
- Affected Vendor/Software:
Jenkins project - Jenkins Convertigo Mobile Platform Plugin version ?> 1.1
CVE References
Description | Tags ⓘ | Link |
---|---|---|
Jenkins Security Advisory 2022-06-22 | www.jenkins.io text/html |
![]() |
There are currently no QIDs associated with this CVE
Known Affected Software
Vendor | Product | Version |
---|---|---|
Jenkins Project | Jenkins_Convertigo_Mobile_Platform_Plugin | <= 1.1 |
Jenkins Project | Jenkins_Convertigo_Mobile_Platform_Plugin | ?> 1.1 |
No vendor comments have been submitted for this CVE
Social Mentions
Source | Title | Posted (UTC) |
---|---|---|
![]() |
CVE-2022-34199 : Jenkins Convertigo Mobile Platform Plugin 1.1 and earlier stores passwords unencrypted in job conf… twitter.com/i/web/status/1… | 2022-06-22 14:55:05 |
![]() |
Jenkins - CVE-2022-34199: jenkins.io/security/advis… | 2022-06-23 19:00:12 |
![]() |
*VULNERABILITY* CVE-2022-34199 CW.cyberwire.info/SSknv5 #cybersecurity #vulnerability #cyberwire | 2022-06-23 23:07:02 |
![]() |
CVE-2022-34199 | 2022-06-22 15:38:21 |