Lucene search

K
osvGoogleOSV:GHSA-JVR5-R663-QXGW
HistoryMay 13, 2022 - 1:15 a.m.

Jenkins Sametime Plugin stores credentials in plain text

2022-05-1301:15:03
Google
osv.dev
5

6.7 Medium

AI Score

Confidence

High

0.003 Low

EPSS

Percentile

66.2%

Jenkins Sametime Plugin stores credentials unencrypted in its global configuration file hudson.plugins.sametime.im.transport.SametimePublisher.xml on the Jenkins controller. These credentials can be viewed by users with access to the Jenkins controller file system.

CPENameOperatorVersion
org.jenkins-ci.plugins:sametimeeq0.4

6.7 Medium

AI Score

Confidence

High

0.003 Low

EPSS

Percentile

66.2%

Related for OSV:GHSA-JVR5-R663-QXGW