Jenkins Configuration as Code Plugin has Insufficiently Protected Credentials
High severity
GitHub Reviewed
Published
May 13, 2022
to the GitHub Advisory Database
•
Updated Jan 29, 2023
Package
Affected versions
< 0.8-alpha
Patched versions
0.8-alpha
Description
Published by the National Vulnerability Database
Jun 26, 2018
Published to the GitHub Advisory Database
May 13, 2022
Reviewed
Nov 8, 2022
Last updated
Jan 29, 2023
A exposure of sensitive information vulnerability exists in Jenkins Configuration as Code Plugin 0.7-alpha and earlier in DataBoundConfigurator.java, Attribute.java, BaseConfigurator.java, ExtensionConfigurator.java that allows attackers with access to Jenkins log files to obtain the passwords configured using Configuration as Code Plugin.
References