[MAVEN:GHSA-P68C-XG89-2G5R] Credentials transmitted in plain text by Backlog Plugin

Severity Low
Affected Packages 1
Fixed Packages 1
CVEs 1

Backlog Plugin stores credentials in job config.xml files as part of its configuration.

While the credentials are stored encrypted on disk, they are transmitted in plain text as part of the configuration form by Backlog Plugin 2.4 and earlier. These credentials could be viewed by users with Extended Read permission.

Package Affected Version
pkg:maven/org.jenkins-ci.plugins/backlog < 2.5
Package Fixed Version
pkg:maven/org.jenkins-ci.plugins/backlog = 2.5
ID
MAVEN:GHSA-P68C-XG89-2G5R
Severity
low
URL
https://github.com/advisories/GHSA-p68c-xg89-2g5r
Published
2022-05-24T17:10:29
(2 years ago)
Modified
2023-12-13T13:13:35
(9 months ago)
Rights
Maven Security Team
Other Advisories
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:maven/org.jenkins-ci.plugins/backlog org.jenkins-ci.plugins backlog < 2.5
Fixed pkg:maven/org.jenkins-ci.plugins/backlog org.jenkins-ci.plugins backlog = 2.5
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...