Lucene search

K
osvGoogleOSV:GHSA-PHWR-PMH3-M8G2
HistoryMay 13, 2022 - 1:17 a.m.

Jenkins aws-device-farm Plugin stores credentials in plain text

2022-05-1301:17:44
Google
osv.dev
7
jenkins
aws-device-farm
plugin
credentials
unencrypted
global configuration
file system
software

AI Score

6.7

Confidence

High

EPSS

0.002

Percentile

65.1%

Jenkins aws-device-farm Plugin stores credentials unencrypted in its global configuration file org.jenkinsci.plugins.awsdevicefarm.AWSDeviceFarmRecorder.xml on the Jenkins controller. These credentials can be viewed by users with access to the Jenkins controller file system.

AI Score

6.7

Confidence

High

EPSS

0.002

Percentile

65.1%

Related for OSV:GHSA-PHWR-PMH3-M8G2