GHSA-9h79-5m2f-mqj2
Dashboard / Vulnerabilities / GHSA-9h79-5m2f-mqj2
Summary: Squash TM Publisher (Squash4Jenkins) Plugin stores passwords stored in plain text
Details: Squash TM Publisher (Squash4Jenkins) Plugin 1.0.0 and earlier stores passwords unencrypted in its global configuration file `org.jenkinsci.squashtm.core.SquashTMPublisher.xml` on the Jenkins controller as part of its configuration. These passwords can be viewed by users with access to the Jenkins controller file system.
References: https://nvd.nist.gov/vuln/detail/CVE-2022-34213, https://github.com/jenkinsci/squashtm-publisher-plugin, https://www.jenkins.io/security/advisory/2022-06-22/#SECURITY-2089
Affected packages
Package
Name: org.jenkins-ci.plugins:squashtm-publisher
Purl: pkg:maven/org.jenkins-ci.plugins/squashtm-publisher
Affected ranges
Type: ECOSYSTEM
Events:
