[MAVEN:GHSA-F6G8-PXVP-9328] Jenkins Inedo ProGet Plugin Plugin has Cleartext Transmission of Sensitive Information

Severity Low
Affected Packages 1
Fixed Packages 1
CVEs 1

Inedo ProGet Plugin Plugin stores a service password in its global Jenkins configuration.

While the password is stored encrypted on disk, it was transmitted in plain text as part of the configuration form. This could result in exposure of the password through browser extensions, cross-site scripting vulnerabilities, and similar situations.

Inedo ProGet Plugin Plugin now encrypts the password transmitted to administrators viewing the global configuration form.

Package Affected Version
pkg:maven/com.inedo.proget/inedo-proget < 1.3
Package Fixed Version
pkg:maven/com.inedo.proget/inedo-proget = 1.3
ID
MAVEN:GHSA-F6G8-PXVP-9328
Severity
low
URL
https://github.com/advisories/GHSA-f6g8-pxvp-9328
Published
2022-05-24T16:56:45
(2 years ago)
Modified
2023-12-13T10:13:28
(9 months ago)
Rights
Maven Security Team
Other Advisories
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:maven/com.inedo.proget/inedo-proget com.inedo.proget inedo-proget < 1.3
Fixed pkg:maven/com.inedo.proget/inedo-proget com.inedo.proget inedo-proget = 1.3
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...