GHSA-rfc8-wrrf-wp3w
Dashboard / Vulnerabilities / GHSA-rfc8-wrrf-wp3w
Summary: Jenkins Azure PublisherSettings Credentials Plugin stored credentials in plain text
Details: Jenkins Azure PublisherSettings Credentials Plugin stored the service management certificate unencrypted in credentials.xml on the Jenkins controller. These credentials could be viewed by users with access to the Jenkins controller file system. Azure PublisherSettings Credentials Plugin has been deprecated. Azure PublisherSettings Credentials Plugin 1.5 no longer provides any user features and we recommend the plugin be uninstalled.
References: https://nvd.nist.gov/vuln/detail/CVE-2019-10303, https://jenkins.io/security/advisory/2019-04-17/#SECURITY-844, https://web.archive.org/web/20200227075952/http://www.securityfocus.com/bid/108045
Affected packages
Package
Name: org.jenkins-ci.plugins:azure-publishersettings-credentials
Purl: pkg:maven/org.jenkins-ci.plugins/azure-publishersettings-credentials
Affected ranges
Type: ECOSYSTEM
Events:
