[MAVEN:GHSA-M59Q-VGQ9-75CR] Password stored in plain text by Jenkins RQM Plugin

Severity Low
Affected Packages 1
CVEs 1

RQM Plugin 2.8 and earlier stores a password unencrypted in its global configuration file net.praqma.jenkins.rqm.RqmBuilder.xml on the Jenkins controller as part of its configuration.

This password can be viewed by users with access to the Jenkins controller file system.

Package Affected Version
pkg:maven/net.praqma/rqm-plugin <= 2.8
ID
MAVEN:GHSA-M59Q-VGQ9-75CR
Severity
low
URL
https://github.com/advisories/GHSA-m59q-vgq9-75cr
Published
2022-07-01T00:01:08
(2 years ago)
Modified
2023-11-22T22:03:50
(10 months ago)
Rights
Maven Security Team
Other Advisories
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:maven/net.praqma/rqm-plugin net.praqma rqm-plugin <= 2.8
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...