Lucene search

K
osvGoogleOSV:GHSA-CCWP-633J-G29V
HistoryMay 24, 2022 - 5:27 p.m.

Passwords stored in plain text by Jenkins ReadyAPI Functional Testing Plugin

2022-05-2417:27:07
Google
osv.dev
13
jenkins
readyapi
functional testing
plugin
passwords
plain text
configuration
encrypted
attackers
extended read permission

EPSS

0.001

Percentile

28.4%

ReadyAPI Functional Testing Plugin 1.3 and earlier stores project passwords unencrypted in job config.xml files as part of its configuration. These project passwords can be viewed by attackers with Extended Read permission or access to the Jenkins controller file system.

ReadyAPI Functional Testing Plugin 1.4 stores project passwords encrypted once affected job configurations are saved again.

EPSS

0.001

Percentile

28.4%

Related for OSV:GHSA-CCWP-633J-G29V