Lucene search

K
osvGoogleOSV:GHSA-RWRX-HRF2-V577
HistoryMay 13, 2022 - 1:15 a.m.

Jenkins Serena SRA Deploy Plugin stores credentials in plain text

2022-05-1301:15:02
Google
osv.dev
10
jenkins
serena sra deploy plugin
credentials
plain text
global configuration file
unencrypted
file system
software

AI Score

6.7

Confidence

High

EPSS

0.002

Percentile

65.1%

Jenkins Serena SRA Deploy Plugin stores credentials unencrypted in its global configuration file com.urbancode.ds.jenkins.plugins.serenarapublisher.UrbanDeployPublisher.xml on the Jenkins controller. These credentials can be viewed by users with access to the Jenkins controller file system.

AI Score

6.7

Confidence

High

EPSS

0.002

Percentile

65.1%

Related for OSV:GHSA-RWRX-HRF2-V577