GHSA-6fv3-w7j6-5xfc
Dashboard / Vulnerabilities / GHSA-6fv3-w7j6-5xfc
Summary: Jenkins Sonar Gerrit Plugin stores credentials unencrypted
Details: Jenkins Sonar Gerrit Plugin stores credentials unencrypted in job config.xml files on the Jenkins master where they can be viewed by users with Extended Read permission, or access to the master file system.
References: https://nvd.nist.gov/vuln/detail/CVE-2019-10467, https://github.com/jenkinsci/sonar-gerrit-plugin/commit/d86de84131660051de7a90195478761b7d087630, https://github.com/jenkinsci/sonar-gerrit-plugin, https://jenkins.io/security/advisory/2019-10-23/#SECURITY-1003, http://www.openwall.com/lists/oss-security/2019/10/23/2
Affected packages
Package
Name: org.jenkins-ci.plugins:sonar-gerrit
Purl: pkg:maven/org.jenkins-ci.plugins/sonar-gerrit
Affected ranges
Type: ECOSYSTEM
Events:
