CVE-2022-34802
Description
Jenkins RocketChat Notifier Plugin 1.5.2 and earlier stores the login password and webhook token unencrypted in its global configuration file, exposing them to users with file system access.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Jenkins RocketChat Notifier Plugin 1.5.2 and earlier stores the login password and webhook token unencrypted in its global configuration file, exposing them to users with file system access.
Vulnerability
Jenkins RocketChat Notifier Plugin versions 1.5.2 and earlier store the login password and webhook token in plaintext (unencrypted) in the plugin's global configuration file on the Jenkins controller [1][2]. This configuration file is accessible to any user who has read access to the controller's file system, regardless of their Jenkins permissions [2].
Exploitation
An attacker with access to the Jenkins controller file system (e.g., through a compromised Jenkins agent, an authenticated user with file read permissions, or via another vulnerability that enables file system access) can read the global configuration file for the plugin and extract the stored login password and webhook token [1][2]. No additional authentication or user interaction is required beyond the initial file system access [2].
Impact
Successful exploitation results in the disclosure of sensitive credentials—the login password and webhook token used by the plugin to authenticate with RocketChat [1][2]. An attacker could use these credentials to impersonate the Jenkins controller in communications with RocketChat, potentially sending malicious notifications, altering configuration, or gaining further access to the RocketChat instance [1][2].
Mitigation
Jenkins released updated versions of the RocketChat Notifier Plugin that encrypt the stored credentials; users should upgrade to a fixed version (e.g., later than 1.5.2) as described in the official Jenkins security advisory [1]. As a workaround, administrators can restrict file system access to the Jenkins controller to only trusted users and review file permissions on the configuration file [1]. The vulnerability is listed in the NVD with a CVSS v3.1 score of 5.5 (medium) for confidentiality impact [2].
AI Insight generated on May 21, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.jenkins-ci.plugins:rocketchatnotifierMaven | <= 1.5.2 | — |
Affected products
2- Jenkins project/Jenkins RocketChat Notifier Pluginv5Range: unspecified
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- github.com/advisories/GHSA-pgp9-x83g-v8x8ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2022-34802ghsaADVISORY
- www.jenkins.io/security/advisory/2022-06-30/ghsax_refsource_CONFIRMWEB
News mentions
0No linked articles in our index yet.