Jenkins jira-ext Plugin stores credentials unencrypted
High severity
GitHub Reviewed
Published
May 24, 2022
to the GitHub Advisory Database
•
Updated Dec 5, 2023
Description
Published by the National Vulnerability Database
Apr 18, 2019
Published to the GitHub Advisory Database
May 24, 2022
Reviewed
May 19, 2023
Last updated
Dec 5, 2023
Jenkins jira-ext Plugin 0.8 and earlier stored credentials unencrypted in its global configuration file
hudson.plugins.jira.JiraProjectProperty.xml
on the Jenkins master. These credentials could be viewed by users with access to the Jenkins master file system.jira-ext Plugin version 0.9 stores credentials encrypted.
References