CVE-2022-34807

Publication date

2022-06-30 17:48:43

Family

jenkins

State

PUBLISHED

Description

Jenkins Elasticsearch Query Plugin 1.2 and earlier stores a password unencrypted in its global configuration file on the Jenkins controller where it can be viewed by users with access to the Jenkins controller file system.