QID 996813

Date Published: 2024-01-29

QID 996813: Java (Maven) Security Update for org.jenkins-ci.plugins:snsnotify (GHSA-84p4-7mxc-7phj)

Jenkins Amazon SNS Build Notifier Plugin stores credentials unencrypted in its global configuration file org.jenkinsci.plugins.snsnotify.AmazonSNSNotifier.xml on the Jenkins controller. These credentials can be viewed by users with access to the Jenkins controller file system.

Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.

  • CVSS V3 rated as Critical - 8.8 severity.
  • CVSS V2 rated as Medium - 4 severity.
  • Solution
    Refer to Github security advisory GHSA-84p4-7mxc-7phj for updates and patch information.
    Vendor References

    CVEs related to QID 996813

    Software Advisories
    Advisory ID Software Component Link
    GHSA-84p4-7mxc-7phj org.jenkins-ci.plugins:snsnotify URL Logo github.com/advisories/GHSA-84p4-7mxc-7phj