CyberAlerts is shutting down on June 30th, 2025. Thank you for your support!

CVE-2024-34147: Jenkins Telegram Bot Plugin 1.4.0 and earlier stores the Telegram Bot token unencrypted in its global configuration file on the Jenkins controller...

Description

Jenkins Telegram Bot Plugin 1.4.0 and earlier stores the Telegram Bot token unencrypted in its global configuration file on the Jenkins controller where it can be viewed by users with access to the Jenkins controller file system.

Classification

CVE ID: CVE-2024-34147

Affected Products

Vendor: Jenkins Project

Product: Jenkins Telegram Bot Plugin

Exploit Prediction Scoring System (EPSS)

EPSS Score: 0.04% (probability of being exploited)

EPSS Percentile: 11.98% (scored less or equal to compared to others)

EPSS Date: 2025-03-14 (when was this score calculated)

References

https://www.jenkins.io/security/advisory/2024-05-02/#SECURITY-3294
http://www.openwall.com/lists/oss-security/2024/05/02/3

Timeline