[MAVEN:GHSA-PXV2-MFQ7-VHP6] Jenkins Inedo BuildMaster Plugin showed plain text password in configuration form

Severity Low
Affected Packages 1
Fixed Packages 1
CVEs 1

Jenkins Inedo BuildMaster Plugin Plugin stores a service password in its global Jenkins configuration.

While the password is stored encrypted on disk, it was transmitted in plain text as part of the configuration form. This could result in exposure of the password through browser extensions, cross-site scripting vulnerabilities, and similar situations.

Inedo BuildMaster Plugin Plugin now encrypts the password transmitted to administrators viewing the global configuration form.

Package Affected Version
pkg:maven/com.inedo.proget/inedo-proget < 2.5.0
Package Fixed Version
pkg:maven/com.inedo.proget/inedo-proget = 2.5.0
ID
MAVEN:GHSA-PXV2-MFQ7-VHP6
Severity
low
URL
https://github.com/advisories/GHSA-pxv2-mfq7-vhp6
Published
2022-05-24T16:56:45
(2 years ago)
Modified
2023-10-26T23:04:38
(10 months ago)
Rights
Maven Security Team
Other Advisories
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:maven/com.inedo.proget/inedo-proget com.inedo.proget inedo-proget < 2.5.0
Fixed pkg:maven/com.inedo.proget/inedo-proget com.inedo.proget inedo-proget = 2.5.0
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...