Lucene search

K
osvGoogleOSV:GHSA-4X65-4FJX-R7M6
HistoryJan 26, 2023 - 9:30 p.m.

Plaintext storage of Access Token in Jenkins GitHub Pull Request Coverage Status Plugin

2023-01-2621:30:18
Google
osv.dev
19
jenkins
github
pull request
coverage status
access token
plaintext storage
security vulnerability
configuration file
unencrypted storage
jenkins controller file system
sonar password

CVSS3

5.5

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

EPSS

0

Percentile

13.2%

Jenkins GitHub Pull Request Coverage Status Plugin 2.2.0 and earlier stores the GitHub Personal Access Token, Sonar access token and Sonar password unencrypted in its global configuration file on the Jenkins controller where they can be viewed by users with access to the Jenkins controller file system.

CVSS3

5.5

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

EPSS

0

Percentile

13.2%

Related for OSV:GHSA-4X65-4FJX-R7M6