Lucene search

K
osvGoogleOSV:GHSA-7HP3-5W4X-8F7C
HistoryMay 24, 2022 - 4:58 p.m.

Jenkins SOASTA CloudTest Plugin stores API token in plain text

2022-05-2416:58:50
Google
osv.dev
5
jenkins
soasta cloudtest
plugin
api token
unencrypted
global configuration
credentials
file system
advisory
publication

AI Score

6.6

Confidence

High

EPSS

0.001

Percentile

22.0%

Jenkins SOASTA CloudTest Plugin stores credentials unencrypted in its global configuration file com.soasta.jenkins.CloudTestServer.xml on the Jenkins controller. These credentials could be viewed by users with access to the Jenkins controller file system.

As of publication of this advisory there is no fix.

AI Score

6.6

Confidence

High

EPSS

0.001

Percentile

22.0%

Related for OSV:GHSA-7HP3-5W4X-8F7C