Lucene search

K
osvGoogleOSV:GHSA-C7P6-X2P3-3WPH
HistoryMay 13, 2022 - 1:15 a.m.

Jenkins youtrack-plugin Plugin stored credentials in plain text

2022-05-1301:15:06
Google
osv.dev
5

6.5 Medium

AI Score

Confidence

High

0.003 Low

EPSS

Percentile

66.2%

Jenkins youtrack-plugin Plugin stored credentials unencrypted in its global configuration file org.jenkinsci.plugins.youtrack.YouTrackProjectProperty.xml on the Jenkins controller. These credentials could be viewed by users with access to the Jenkins controller file system.

youtrack-plugin Plugin now stores credentials encrypted.

6.5 Medium

AI Score

Confidence

High

0.003 Low

EPSS

Percentile

66.2%

Related for OSV:GHSA-C7P6-X2P3-3WPH