Description


Jenkins view-cloner Plugin 1.1 and earlier stores passwords unencrypted in job config.xml files on the Jenkins controller where they can be viewed by users with Extended Read permission, or access to the Jenkins controller file system.

Related CPE's


a

jenkins

view-cloner

2

Weaknesses



CWE-312

134c704f-9b21-4f2e-91b3-4a467353bcc0

Secondary

CWE-312

CVSS impact metrics


CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

6.5 · Medium

Information


Source identifier

[email protected]

Vulnerability status

Modified

Published

2023-01-26T20:18:18.487Z

3 years ago

Last modified

2025-04-02T12:15:41.323Z

1 year ago