GHSA-hhhh-69qp-5p2v
Dashboard / Vulnerabilities / GHSA-hhhh-69qp-5p2v
Summary: Jenkins Fortify on Demand Plugin stores credentials in plain text
Details: Jenkins Fortify on Demand Plugin stores credentials unencrypted in job `config.xml` files on the Jenkins controller. These credentials can be viewed by users with Extended Read permission or access to the Jenkins controller file system.
References: https://nvd.nist.gov/vuln/detail/CVE-2019-10449, https://github.com/jenkinsci/fortify-on-demand-uploader-plugin/commit/277642040362bcc64df163bfc1ab48f7763c2853, https://github.com/jenkinsci/fortify-on-demand-uploader-plugin/commit/83b23662dc0ce9486b904e282bd8047496730819, https://github.com/jenkinsci/fortify-on-demand-uploader-plugin, https://jenkins.io/security/advisory/2019-10-16/#SECURITY-1433
Affected packages
Package
Name: org.jenkins-ci.plugins:fortify-on-demand-uploader
Purl: pkg:maven/org.jenkins-ci.plugins/fortify-on-demand-uploader
Affected ranges
Type: ECOSYSTEM
Events:
