Loading HuntDB...

GHSA-7298-w54j-q7wm

GitHub Security Advisory

Cleartext Storage of Sensitive Information in Jenkins Build Notifications Plugin

✓ GitHub Reviewed LOW Has CVE

Advisory Details

Jenkins Build Notifications Plugin 1.5.0 and earlier transmits tokens in plain text as part of the global Jenkins configuration form, potentially resulting in their exposure.

Affected Packages

Maven tools.devnull:build-notifications
Affected versions: 0 (last affected: 1.5.0)

Related CVEs

Key Information

GHSA ID
GHSA-7298-w54j-q7wm
Published
July 1, 2022 12:01 AM
Last Modified
December 9, 2022 4:57 AM
CVSS Score
2.5 /10
Primary Ecosystem
Maven
Primary Package
tools.devnull:build-notifications
GitHub Reviewed
✓ Yes

Dataset

Last updated: August 25, 2025 6:33 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.