Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2022-41248


Jenkins BigPanda Notifier Plugin 1.4.0 and earlier does not mask the BigPanda API key on the global configuration form, increasing the potential for attackers to observe and capture it.


Published

2022-09-21T16:15:11.277

Last Modified

2025-05-27T19:15:24.107

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 5.3 (MEDIUM)

Weaknesses
  • Type: Primary
    CWE-312
  • Type: Secondary
    CWE-312

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application jenkins bigpanda_notifier ≤ 1.4.0 Yes

References