Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-rfc8-wrrf-wp3w

Опубликовано: 24 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 3.3

Описание

Jenkins Azure PublisherSettings Credentials Plugin stored credentials in plain text

Jenkins Azure PublisherSettings Credentials Plugin stored the service management certificate unencrypted in credentials.xml on the Jenkins controller. These credentials could be viewed by users with access to the Jenkins controller file system.

Azure PublisherSettings Credentials Plugin has been deprecated. Azure PublisherSettings Credentials Plugin 1.5 no longer provides any user features and we recommend the plugin be uninstalled.

Пакеты

Наименование

org.jenkins-ci.plugins:azure-publishersettings-credentials

maven
Затронутые версииВерсия исправления

< 1.5

1.5

EPSS

Процентиль: 21%
0.00067
Низкий

3.3 Low

CVSS3

Дефекты

CWE-522

Связанные уязвимости

CVSS3: 8.8
nvd
почти 7 лет назад

Jenkins Azure PublisherSettings Credentials Plugin 1.2 and earlier stored credentials unencrypted in the credentials.xml file on the Jenkins master where they could be viewed by users with access to the master file system.

EPSS

Процентиль: 21%
0.00067
Низкий

3.3 Low

CVSS3

Дефекты

CWE-522