Insufficiently Protected Credentials Affecting com.ztbsuper:dingding-notifications package, versions [0,]
Do your applications use this vulnerable package?
2 Oct 2019
1 Oct 2019
David Fiser of Trend Micro Nebula working with Trend Micro's Zero Day Initiative
How to fix?
There is no fixed version for
com.ztbsuper:dingding-notifications is a Jenkins config plugin that can notify the build job status to specified groups.
Affected versions of this package are vulnerable to Insufficiently Protected Credentials. Credentials are transmitted in plain text as part of the global Jenkins configuration form, potentially resulting in their exposure.