Описание
Token stored in plain text by DigitalOcean Plugin
Jenkins DigitalOcean Plugin 1.1 and earlier stores a token unencrypted in the global config.xml file on the Jenkins master where it can be viewed by users with access to the master file system.
Пакеты
Наименование
com.dubture.jenkins:digitalocean-plugin
maven
Затронутые версииВерсия исправления
<= 1.1
1.2.0
Связанные уязвимости
CVSS3: 4.3
nvd
почти 6 лет назад
Jenkins DigitalOcean Plugin 1.1 and earlier stores a token unencrypted in the global config.xml file on the Jenkins master where it can be viewed by users with access to the master file system.