VendorsJenkinsbuild_notificationsall versions
Vulnerabilities

Jenkins Build Notifications

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

2CVEs
CVE-2022-34800
Jenkins Build Notifications Plugin 1.5.0 and earlier stores tokens unencrypted in its global configuration files on the Jenkins controller where they can be viewed by users with access to the Jenkins controller file system.
Published 2022-06-30 · Modified
4.3EPSS 0.006
CVE-2022-34801
Jenkins Build Notifications Plugin 1.5.0 and earlier transmits tokens in plain text as part of the global Jenkins configuration form, potentially resulting in their exposure.
Published 2022-06-30 · Modified
4.3EPSS 0.005