GHSA-hf7w-f4h4-9xp8

    Dashboard / Vulnerabilities / GHSA-hf7w-f4h4-9xp8

    GHSA-hf7w-f4h4-9xp8

    Published: 17 May 2022Last Modified: 16 Feb 2024

    Summary: Exposure of Sensitive Information in Jenkins Datadog plugin

    Details: The Datadog Plugin stores an API key to access the Datadog service in the global Jenkins configuration. While the API key is stored encrypted on disk, it was transmitted in plain text as part of the configuration form. This could result in exposure of the API key for example through browser extensions or cross-site scripting vulnerabilities. The Datadog Plugin now encrypts the API key transmitted to administrators viewing the global configuration form.

    Affected packages

    Package

    Name: org.datadog.jenkins.plugins:datadog

    Purl: pkg:maven/org.datadog.jenkins.plugins/datadog

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 0
    Fixed -0.6.2

    Affected versions

    0.2.1

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    GHSA-hf7w-f4h4-9xp8 | CVE-DB