Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2024-34147


Jenkins Telegram Bot Plugin 1.4.0 and earlier stores the Telegram Bot token unencrypted in its global configuration file on the Jenkins controller where it can be viewed by users with access to the Jenkins controller file system.


Published

2024-05-02T14:15:10.447

Last Modified

2025-10-10T15:34:45.500

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 4.3 (MEDIUM)

Weaknesses
  • Type: Secondary
    CWE-522

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application jenkins telegram_bot ≤ 1.4.0 Yes

References