Описание
Cleartext Storage of Sensitive Information in Jenkins ElasticBox CI Plugin
Jenkins ElasticBox CI Plugin stores credentials unencrypted in the global config.xml configuration file on the Jenkins master where they can be viewed by users with access to the master file system.
Пакеты
Наименование
com.elasticbox.jenkins-ci.plugins:elasticbox
maven
Затронутые версииВерсия исправления
<= 5.0.1
Отсутствует
Связанные уязвимости
CVSS3: 3.3
nvd
больше 6 лет назад
Jenkins ElasticBox CI Plugin stores credentials unencrypted in the global config.xml configuration file on the Jenkins master where they can be viewed by users with access to the master file system.