Improper Removal of Sensitive Information Before Storage or Transfer
CVE-2022-25187
Summary
Jenkins Support Core Plugin 2.79 and earlier does not redact some sensitive information in the support bundle.
- LOW
- NETWORK
- NONE
- UNCHANGED
- NONE
- LOW
- HIGH
- NONE
CWE-212 - Improper Removal of Sensitive Information Before Storage or Transfer
The product stores, transfers, or shares a resource that contains sensitive information, but it does not properly remove that information before the product makes the resource available to unauthorized actors.
References
Advisory Timeline
- Published