Description


Jenkins GitHub Pull Request Coverage Status Plugin 2.2.0 and earlier stores the GitHub Personal Access Token, Sonar access token and Sonar password unencrypted in its global configuration file on the Jenkins controller where they can be viewed by users with access to the Jenkins controller file system.

Weaknesses



CWE-312

134c704f-9b21-4f2e-91b3-4a467353bcc0

Secondary

CWE-312

CVSS impact metrics


CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

5.5 · Medium

Information


Source identifier

[email protected]

Vulnerability status

Modified

Published

2023-01-26T20:18:17.960Z

3 years ago

Last modified

2025-04-02T12:15:39.693Z

1 year ago