[MAVEN:GHSA-RWRX-HRF2-V577] Jenkins Serena SRA Deploy Plugin stores credentials in plain text

Severity Low
Affected Packages 1
CVEs 1

Jenkins Serena SRA Deploy Plugin stores credentials unencrypted in its global configuration file com.urbancode.ds.jenkins.plugins.serenarapublisher.UrbanDeployPublisher.xml on the Jenkins controller. These credentials can be viewed by users with access to the Jenkins controller file system.

Package Affected Version
pkg:maven/com.urbancode.ds.jenkins.plugins/sra-deploy <= 1.4.2.4
ID
MAVEN:GHSA-RWRX-HRF2-V577
Severity
low
URL
https://github.com/advisories/GHSA-rwrx-hrf2-v577
Published
2022-05-13T01:15:02
(2 years ago)
Modified
2023-10-26T16:53:16
(10 months ago)
Rights
Maven Security Team
Other Advisories
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:maven/com.urbancode.ds.jenkins.plugins/sra-deploy com.urbancode.ds.jenkins.plugins sra-deploy <= 1.4.2.4
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...