Cleartext storage of sensitive information in RocketChat Notifier - CVE-2022-34802
Published: July 7, 2022
RocketChat Notifier
Jenkins
Description
The vulnerability allows a local user to gain access to potentially sensitive information.
The vulnerability exists due to the affected plugin stores the login password and webhook token unencrypted in its global configuration file RocketChatNotifier.xml on the Jenkins controller as part of its configuration. A local user can gain unauthorized access to sensitive information on the system.