CVE-2022-34202
Published on: Not Yet Published
Last Modified on: 06/29/2022 07:39:00 PM UTC
Certain versions of Easyqa from Jenkins contain the following vulnerability:
Jenkins EasyQA Plugin 1.0 and earlier stores user passwords unencrypted in its global configuration file on the Jenkins controller where they can be viewed by users with access to the Jenkins controller file system.
- CVE-2022-34202 has been assigned by
[email protected] to track the vulnerability - currently rated as MEDIUM severity.
- Affected Vendor/Software:
Jenkins project - Jenkins EasyQA Plugin version <= 1.0
- Affected Vendor/Software:
Jenkins project - Jenkins EasyQA Plugin version ?> 1.0
CVSS3 Score: 6.5 - MEDIUM
Attack Vector ⓘ |
Attack Complexity |
Privileges Required |
User Interaction |
---|---|---|---|
NETWORK | LOW | LOW | NONE |
Scope | Confidentiality Impact |
Integrity Impact |
Availability Impact |
UNCHANGED | HIGH | NONE | NONE |
CVSS2 Score: 4 - MEDIUM
Access Vector ⓘ |
Access Complexity |
Authentication |
---|---|---|
NETWORK | LOW | SINGLE |
Confidentiality Impact |
Integrity Impact |
Availability Impact |
PARTIAL | NONE | NONE |
CVE References
Description | Tags ⓘ | Link |
---|---|---|
Jenkins Security Advisory 2022-06-22 | www.jenkins.io text/html |
![]() |
There are currently no QIDs associated with this CVE
Known Affected Configurations (CPE V2.3)
Type | Vendor | Product | Version | Update | Edition | Language |
---|---|---|---|---|---|---|
Application | Jenkins | Easyqa | All | All | All | All |
- cpe:2.3:a:jenkins:easyqa:*:*:*:*:*:jenkins:*:*:
No vendor comments have been submitted for this CVE
Social Mentions
Source | Title | Posted (UTC) |
---|---|---|
![]() |
CVE-2022-34202 : Jenkins EasyQA Plugin 1.0 and earlier stores user passwords unencrypted in its global configuratio… twitter.com/i/web/status/1… | 2022-06-22 14:56:13 |
![]() |
Jenkins - CVE-2022-34202: jenkins.io/security/advis… | 2022-06-23 19:00:13 |
![]() |
*VULNERABILITY* CVE-2022-34202 CW.cyberwire.info/SSkntp #cybersecurity #vulnerability #cyberwire | 2022-06-23 23:06:41 |
![]() |
CVE-2022-34202 | 2022-06-22 15:38:24 |