[JENKINS:SECURITY-1523] Credentials transmitted in plain text by `sonar-quality-gates`

Severity Low
Affected Packages 2
CVEs 1

sonar-quality-gates stores credentials in its global configuration file org.quality.gates.jenkins.plugin.GlobalConfig.xml on the Jenkins controller as part of its configuration.

While the credentials are stored encrypted on disk, they are transmitted in plain text as part of the configuration form by sonar-quality-gates 1.3.1 and earlier.
This can result in exposure of the credential through browser extensions, cross-site scripting vulnerabilities, and similar situations.

As of publication of this advisory, there is no fix.

ID
JENKINS:SECURITY-1523
Severity
low
Published
2020-03-09T00:00:00
(4 years ago)
Modified
2020-03-09T00:00:00
(4 years ago)
Rights
Jenkins Security Team
Other Advisories
Source # ID Name URL
Plugin repository sonar-quality-gates repository https://github.com/jenkinsci/sonar-quality-gates-plugin
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:maven/org.jenkins-ci.plugins/sonar-quality-gates org.jenkins-ci.plugins sonar-quality-gates <= 1.3.1
Affected pkg:github/jenkinsci/sonar-quality-gates-plugin jenkinsci sonar-quality-gates-plugin <= 1.3.1
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...