Lucene search

K
osvGoogleOSV:GHSA-8MJP-8C2X-3G7W
HistoryMay 24, 2022 - 5:01 p.m.

Jenkins QMetry for JIRA Plugin stored credentials in plain text

2022-05-2417:01:41
Google
osv.dev
4

6.5 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

42.8%

Jenkins QMetry for JIRA - Test Management Plugin stored credentials unencrypted in job config.xml files on the Jenkins controller as part of its post-build step configuration. This credential could be viewed by users with Extended Read permission or access to the Jenkins controller file system.

QMetry for JIRA - Test Management Plugin now stores these credentials encrypted once the job configuration is saved again.

6.5 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

42.8%

Related for OSV:GHSA-8MJP-8C2X-3G7W