GHSA-jp8r-jh5j-cgwf
Dashboard / Vulnerabilities / GHSA-jp8r-jh5j-cgwf
Summary: Jenkins CodeScan Plugin has Insufficiently Protected Credentials
Details: CodeScan Plugin stores an API key unencrypted in its global configuration file `com.villagechief.codescan.jenkins.CodeScanBuilder.xml` on the Jenkins controller. This API key can be viewed by users with access to the Jenkins controller file system. As of publication of this advisory, there is no fix.
References: https://nvd.nist.gov/vuln/detail/CVE-2019-10423, https://github.com/jenkinsci/codescan-plugin, https://jenkins.io/security/advisory/2019-09-25/#SECURITY-1551, http://www.openwall.com/lists/oss-security/2019/09/25/3
Affected packages
Package
Name: com.villagechief.codescan.jenkins:codescan
Purl: pkg:maven/com.villagechief.codescan.jenkins/codescan
Affected ranges
Type: ECOSYSTEM
Events:
