CVE-2023-50776

CVSS v3.1 4.3 (Medium)
43% Progress
EPSS 0.04 % (14th)
0.04% Progress
Affected Products 1
Advisories 2

Jenkins PaaSLane Estimate Plugin 1.0.4 and earlier stores PaaSLane authentication tokens unencrypted in job config.xml files on the Jenkins controller where they can be viewed by users with Item/Extended Read permission or access to the Jenkins controller file system.

Weaknesses
CWE-312
Cleartext Storage of Sensitive Information
CVE Status
PUBLISHED
CNA
Jenkins Project
Published Date
2023-12-13 18:15:44
(9 months ago)
Updated Date
2023-12-18 19:11:13
(9 months ago)

Affected Products

Loading...
Loading...
Loading...

Configuration #1

    CPE23 From Up To
  Jenkins Paaslane Estimate for Jenkins 1.0.4 and prior versions cpe:2.3:a:jenkins:paaslane_estimate::*:*:*:*:jenkins <= 1.0.4
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...