Description


Jenkins TestQuality Updater Plugin 1.3 and earlier stores the TestQuality Updater password unencrypted in its global configuration file on the Jenkins controller where it can be viewed by users with access to the Jenkins controller file system.

Weaknesses



CWE-312

134c704f-9b21-4f2e-91b3-4a467353bcc0

Secondary

CWE-312

CVSS impact metrics


CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

5.5 · Medium

Information


Source identifier

[email protected]

Vulnerability status

Modified

Published

2023-01-26T20:18:18.807Z

3 years ago

Last modified

2025-04-02T12:15:41.953Z

11 months ago