[MAVEN:GHSA-HM57-4QPX-F734] Credentials transmitted in plain text by Jenkins DeployHub Plugin

Severity Low
Affected Packages 1
CVEs 1

DeployHub Plugin stores credentials in job config.xml files as part of its configuration.

While the credentials are stored encrypted on disk, they are transmitted in plain text as part of the configuration form by DeployHub Plugin 8.0.14 and earlier. These credentials could be viewed by users with Extended Read permission.

Package Affected Version
pkg:maven/com.openmake/deployhub <= 8.0.14
ID
MAVEN:GHSA-HM57-4QPX-F734
Severity
low
URL
https://github.com/advisories/GHSA-hm57-4qpx-f734
Published
2022-05-24T17:10:29
(2 years ago)
Modified
2023-01-29T05:01:21
(19 months ago)
Rights
Maven Security Team
Other Advisories
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:maven/com.openmake/deployhub com.openmake deployhub <= 8.0.14
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...