[MAVEN:GHSA-7HF6-HGGP-VVP9] Jenkins CloudCoreo DeployTime Plugin stores credentials in plain text

Severity Low
Affected Packages 1
CVEs 1

Jenkins CloudCoreo DeployTime Plugin stores credentials unencrypted in its global configuration file com.cloudcoreo.plugins.jenkins.CloudCoreoBuildWrapper.xml on the Jenkins controller. These credentials can be viewed by users with access to the Jenkins controller file system.

ID
MAVEN:GHSA-7HF6-HGGP-VVP9
Severity
low
URL
https://github.com/advisories/GHSA-7hf6-hggp-vvp9
Published
2022-05-13T01:15:03
(2 years ago)
Modified
2023-10-26T15:42:15
(10 months ago)
Rights
Maven Security Team
Other Advisories
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:maven/com.cloudcoreo.plugins/cloudcoreo-deploytime com.cloudcoreo.plugins cloudcoreo-deploytime <= 0.2.3
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...