GHSA-jmp9-f42q-4g85
Dashboard / Vulnerabilities / GHSA-jmp9-f42q-4g85
Summary: Passwords stored in plain text by Harvest SCM Plugin
Details: Harvest SCM Plugin 0.5.1 and earlier stores SCM passwords unencrypted in its global configuration file `hudson.plugins.harvest.HarvestSCM.xml and in job config.xml` files on the Jenkins controller. These credentials can be viewed by users with Extended Read permission (job config.xml only) or access to the Jenkins controller file system (both).
References: https://nvd.nist.gov/vuln/detail/CVE-2020-2130, https://github.com/jenkinsci/harvest-plugin, https://jenkins.io/security/advisory/2020-02-12/#SECURITY-1553, http://www.openwall.com/lists/oss-security/2020/02/12/3
Affected packages
Package
Name: org.jenkins-ci.plugins:harvest
Purl: pkg:maven/org.jenkins-ci.plugins/harvest
Affected ranges
Type: ECOSYSTEM
Events:
