GHSA-5r5f-hcwf-r9jh
Dashboard / Vulnerabilities / GHSA-5r5f-hcwf-r9jh
Summary: Secret stored in plain text by Jenkins GitHub Coverage Reporter Plugin
Details: GitHub Coverage Reporter Plugin 1.10 and earlier stores a GitHub access token in plain text in its global configuration file `io.jenkins.plugins.gcr.PluginConfiguration.xml`. This token can be viewed by users with access to the Jenkins controller file system.
References: https://nvd.nist.gov/vuln/detail/CVE-2020-2212, https://github.com/jenkinsci/github-coverage-reporter-plugin, https://jenkins.io/security/advisory/2020-07-02/#SECURITY-1632, http://www.openwall.com/lists/oss-security/2020/07/02/7
Affected packages
Package
Name: io.jenkins.plugins:github-coverage-reporter
Purl: pkg:maven/io.jenkins.plugins/github-coverage-reporter
Affected ranges
Type: ECOSYSTEM
Events:
