Lucene search

K
osvGoogleOSV:GHSA-793W-Q2H5-8H5J
HistoryMay 24, 2022 - 5:01 p.m.

Jenkins QMetry for JIRA Plugin shows plain text password in configuration form

2022-05-2417:01:41
Google
osv.dev
2

6.2 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

28.4%

Jenkins QMetry for JIRA - Test Management Plugin stores a credential as part of its post-build step configuration.

While the password is stored encrypted on disk since QMetry for JIRA - Test Management Plugin 1.13, it is transmitted in plain text as part of the configuration form. This can result in exposure of the password through browser extensions, cross-site scripting vulnerabilities, and similar situations.

6.2 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

28.4%

Related for OSV:GHSA-793W-Q2H5-8H5J