Lucene search

K
osvGoogleOSV:GHSA-757G-M98V-6R49
HistoryMay 24, 2022 - 4:58 p.m.

Jenkins Sofy.AI Plugin stores API token in plain text

2022-05-2416:58:49
Google
osv.dev
5
jenkins
sofy.ai
api token
plaintext
job config.xml
jenkins controller
extended read permission
file system
security advisory
software

AI Score

6.6

Confidence

High

EPSS

0.001

Percentile

22.0%

Jenkins Sofy.AI Plugin stores an API token unencrypted in job config.xml files on the Jenkins controller. This token can be viewed by users with Extended Read permission or access to the Jenkins controller file system.

As of publication of this advisory there is no fix.

AI Score

6.6

Confidence

High

EPSS

0.001

Percentile

22.0%

Related for OSV:GHSA-757G-M98V-6R49