Skip to main content

Vendor/product archive

jenkins / dingding_json_pusher CVEs

Beta · best-effort

2 CVEs tagged to jenkins / dingding_json_pusher0 Critical, 0 High, 2 Medium, 0 Low, 0 Unrated.

CVE-2023-50773

Published Dec 13, 2023

Jenkins Dingding JSON Pusher Plugin 2.0 and earlier does not mask access tokens displayed on the job configuration form, increasing the potential for attackers to observe and capt…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-50772

Published Dec 13, 2023

Jenkins Dingding JSON Pusher Plugin 2.0 and earlier stores access tokens unencrypted in job config.xml files on the Jenkins controller where they can be viewed by users with Item/…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-2 of 2 CVEsPage 1 of 1