#VU65054 Cleartext storage of sensitive information in HPE Network Virtualization - CVE-2022-34816
Published: July 8, 2022
HPE Network Virtualization
Jenkins
Description
The vulnerability allows a local user to gain access to potentially sensitive information.
The vulnerability exists due to the affected plugin stores passwords unencrypted in its global configuration file org.jenkinsci.plugins.nvemulation.plugin.NvEmulationBuilder.xml on the Jenkins controller as part of its configuration. A local user can gain unauthorized access to sensitive information on the system.