GHSA-c7p6-x2p3-3wph
Dashboard / Vulnerabilities / GHSA-c7p6-x2p3-3wph
Summary: Jenkins youtrack-plugin Plugin stored credentials in plain text
Details: Jenkins youtrack-plugin Plugin stored credentials unencrypted in its global configuration file `org.jenkinsci.plugins.youtrack.YouTrackProjectProperty.xml` on the Jenkins controller. These credentials could be viewed by users with access to the Jenkins controller file system. youtrack-plugin Plugin now stores credentials encrypted.
References: https://nvd.nist.gov/vuln/detail/CVE-2019-10287, https://jenkins.io/security/advisory/2019-04-03/#SECURITY-963, http://www.openwall.com/lists/oss-security/2019/04/12/2
Affected packages
Package
Name: org.jenkins-ci.plugins:youtrack-plugin
Purl: pkg:maven/org.jenkins-ci.plugins/youtrack-plugin
Affected ranges
Type: ECOSYSTEM
Events:
