GHSA-64jr-ggw8-h9jc
Dashboard / Vulnerabilities / GHSA-64jr-ggw8-h9jc
Summary: Credentials stored in plain text by debian-package-builder Plugin
Details: debian-package-builder Plugin 1.6.11 and earlier stores a GPG passphrase unencrypted in its global configuration file `ru.yandex.jenkins.plugins.debuilder.DebianPackageBuilder.xml` on the Jenkins controller. This credential can be viewed by users with access to the Jenkins controller file system.
References: https://nvd.nist.gov/vuln/detail/CVE-2020-2125, https://github.com/jenkinsci/debian-package-builder-plugin, https://jenkins.io/security/advisory/2020-02-12/#SECURITY-1558, http://www.openwall.com/lists/oss-security/2020/02/12/3
Affected packages
Package
Name: ru.yandex.jenkins.plugins.debuilder:debian-package-builder
Purl: pkg:maven/ru.yandex.jenkins.plugins.debuilder/debian-package-builder
Affected ranges
Type: ECOSYSTEM
Events:
