GHSA-jrjr-7rf4-3wqh
Dashboard / Vulnerabilities / GHSA-jrjr-7rf4-3wqh
Summary: Password stored in plain text by Jenkins couchdb-statistics Plugin
Details: Jenkins couchdb-statistics Plugin 0.3 and earlier stores its server password unencrypted in its global configuration file `org.jenkinsci.plugins.couchstats.CouchStatsConfig.xml` on the Jenkins controller as part of its configuration. This password can be viewed by users with access to the Jenkins controller file system. couchdb-statistics Plugin 0.4 stores its server password encrypted once its configuration is saved again.
References: https://nvd.nist.gov/vuln/detail/CVE-2020-2291, https://github.com/jenkinsci/couchdb-statistics-plugin, https://www.jenkins.io/security/advisory/2020-10-08/#SECURITY-2065, http://www.openwall.com/lists/oss-security/2020/10/08/5
Affected packages
Package
Name: org.jenkins-ci.plugins:couchdb-statistics
Purl: pkg:maven/org.jenkins-ci.plugins/couchdb-statistics
Affected ranges
Type: ECOSYSTEM
Events:
