CVE-2022-41248

5.3MEDIUM

Jenkins BigPanda Notifier Plugin 1.4.0 and earlier does not mask the BigPanda API key on the global configuration form, increasing the potential for attackers to observe and capture it.

发布于: 9/21/2022更新于: 5/27/2025

描述

Jenkins BigPanda Notifier Plugin 1.4.0 and earlier does not mask the BigPanda API key on the global configuration form, increasing the potential for attackers to observe and capture it.

AI分析AI驱动

受影响产品

jenkinsbigpanda_notifier

参考资料