GHSA-jjmv-6fv4-85vf
Dashboard / Vulnerabilities / GHSA-jjmv-6fv4-85vf
Summary: Jenkins Data Theorem Mobile Security: CI/CD Plugin has Insufficiently Protected Credentials
Details: Data Theorem Mobile Security: CI/CD Plugin stored a proxy password unencrypted in job `config.xml` files on the Jenkins controller. This password could be viewed by users with Extended Read permission, or access to the Jenkins controller file system. Data Theorem Mobile Security: CI/CD Plugin now stores the proxy password encrypted. Existing jobs need to have their configuration saved for existing plain text proxy passwords to be overwritten.
References: https://nvd.nist.gov/vuln/detail/CVE-2019-10413, https://jenkins.io/security/advisory/2019-09-25/#SECURITY-1557, http://www.openwall.com/lists/oss-security/2019/09/25/3
Affected packages
Package
Name: com.datatheorem.mobileappsecurity.jenkins.plugin:datatheorem-mobile-app-security
Purl: pkg:maven/com.datatheorem.mobileappsecurity.jenkins.plugin/datatheorem-mobile-app-security
Affected ranges
Type: ECOSYSTEM
Events:
