GHSA-hfjr-m75m-wmh7
Dashboard / Vulnerabilities / GHSA-hfjr-m75m-wmh7
Summary: Jenkins Zulip Plugin vulnerable to Insufficiently Protected Credentials
Details: Jenkins Zulip Plugin prior to 1.1.1 stored credentials unencrypted in its global configuration file on the Jenkins master where they could be viewed by users with access to the master file system.
References: https://nvd.nist.gov/vuln/detail/CVE-2019-10476, https://github.com/jenkinsci/zulip-plugin/commit/2a9dd6c41c2d913b0414d015b3118e3ddb60bd90, https://github.com/jenkinsci/zulip-plugin, https://github.com/jenkinsci/zulip-plugin/releases/tag/1.1.1, https://jenkins.io/security/advisory/2019-10-23/#SECURITY-1621, http://www.openwall.com/lists/oss-security/2019/10/23/2
Affected packages
Package
Name: org.jenkins-ci.plugins:zulip
Purl: pkg:maven/org.jenkins-ci.plugins/zulip
Affected ranges
Type: ECOSYSTEM
Events:
