[JENKINS:SECURITY-727-1] `qmetry-for-jira-test-management` stored credentials in plain text

Severity Medium
Affected Packages 2
Fixed Packages 2
CVEs 1

qmetry-for-jira-test-management stored credentials unencrypted in job config.xml files on the Jenkins controller as part of its post-build step configuration.
This credential could be viewed by users with Extended Read permission or access to the Jenkins controller file system.

qmetry-for-jira-test-management now stores these credentials encrypted once the job configuration is saved again.

ID
JENKINS:SECURITY-727-1
Severity
medium
Published
2019-11-21T00:00:00
(4 years ago)
Modified
2019-11-21T00:00:00
(4 years ago)
Rights
Jenkins Security Team
Other Advisories
Source # ID Name URL
Plugin repository qmetry-for-jira-test-management repository https://github.com/jenkinsci/qmetry-for-jira-test-management-plugin
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:maven/org.jenkins-ci.plugins/qmetry-for-jira-test-management org.jenkins-ci.plugins qmetry-for-jira-test-management <= 1.12
Fixed pkg:maven/org.jenkins-ci.plugins/qmetry-for-jira-test-management org.jenkins-ci.plugins qmetry-for-jira-test-management = 1.13
Affected pkg:github/jenkinsci/qmetry-for-jira-test-management-plugin jenkinsci qmetry-for-jira-test-management-plugin <= 1.12
Fixed pkg:github/jenkinsci/qmetry-for-jira-test-management-plugin jenkinsci qmetry-for-jira-test-management-plugin = 1.13
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...