Описание
Jenkins Assembla Auth Plugin stores credentials in plain text
Jenkins Assembla Auth Plugin stores credentials unencrypted in the global config.xml configuration file on the Jenkins master where they can be viewed by users with access to the master file system.
Пакеты
Наименование
org.jenkins-ci.plugins:assembla-auth
maven
Затронутые версииВерсия исправления
<= 1.11
1.13
Связанные уязвимости
CVSS3: 8.8
nvd
почти 7 лет назад
Jenkins Assembla Auth Plugin stores credentials unencrypted in the global config.xml configuration file on the Jenkins master where they can be viewed by users with access to the master file system.