[MAVEN:GHSA-Q5CJ-XF99-79M8] Displayed in plain text by Dingding JSON Pusher Plugin

Severity Moderate
Affected Packages 1
CVEs 1

Jenkins Dingding JSON Pusher Plugin 2.0 and earlier does not mask access tokens displayed on the job configuration form, increasing the potential for attackers to observe and capture them.

Package Affected Version
pkg:maven/com.zintow/dingding-json-pusher <= 2.0
ID
MAVEN:GHSA-Q5CJ-XF99-79M8
Severity
moderate
URL
https://github.com/advisories/GHSA-q5cj-xf99-79m8
Published
2023-12-13T18:31:04
(9 months ago)
Modified
2023-12-18T18:39:29
(9 months ago)
Rights
Maven Security Team
Other Advisories
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:maven/com.zintow/dingding-json-pusher com.zintow dingding-json-pusher <= 2.0
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...