GHSA-vwfv-qpw8-83c7
Dashboard / Vulnerabilities / GHSA-vwfv-qpw8-83c7
Summary: Access token stored in plain text by Jenkins SMS Notification Plugin
Details: Jenkins SMS Notification Plugin 1.2 and earlier stores an access token unencrypted in its global configuration file `com.hoiio.jenkins.plugin.SMSNotification.xml` on the Jenkins controller as part of its configuration. This access token can be viewed by users with access to the Jenkins controller file system.
References: https://nvd.nist.gov/vuln/detail/CVE-2020-2297, https://github.com/jenkinsci/sms-plugin, https://www.jenkins.io/security/advisory/2020-10-08/#SECURITY-2054, http://www.openwall.com/lists/oss-security/2020/10/08/5
Affected packages
Package
Name: com.hoiio.jenkins:sms
Purl: pkg:maven/com.hoiio.jenkins/sms
Affected ranges
Type: ECOSYSTEM
Events:
