[JENKINS:SECURITY-1519] Credentials transmitted in plain text by `quality-gates`

Severity Low
Affected Packages 2
CVEs 1

quality-gates stores credentials in its global configuration file quality.gates.jenkins.plugin.GlobalConfig.xml on the Jenkins controller as part of its configuration.

While the credentials are stored encrypted on disk, they are transmitted in plain text as part of the configuration form by quality-gates 2.5 and earlier.
This can result in exposure of the credential through browser extensions, cross-site scripting vulnerabilities, and similar situations.

As of publication of this advisory, there is no fix.

ID
JENKINS:SECURITY-1519
Severity
low
Published
2020-03-09T00:00:00
(4 years ago)
Modified
2020-03-09T00:00:00
(4 years ago)
Rights
Jenkins Security Team
Other Advisories
Source # ID Name URL
Plugin repository quality-gates repository https://github.com/jenkinsci/quality-gates-plugin
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:maven/org.jenkins-ci.plugins/quality-gates org.jenkins-ci.plugins quality-gates <= 2.5
Affected pkg:github/jenkinsci/quality-gates-plugin jenkinsci quality-gates-plugin <= 2.5
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...