Unencrypted Credential Storage in Jenkins Spira Importer Plugin by CloudBees
CVE-2019-16543
5.5MEDIUM
Key Information:
- Vendor
- Jenkins
- Vendor
- CVE Published:
- 21 November 2019
Summary
The Jenkins Spira Importer Plugin versions prior to 3.2.2 store user credentials without encryption in the global configuration file of the Jenkins master. This security flaw allows users with access to the master file system to view these sensitive credentials, potentially leading to unauthorized access and exploitation. Mitigating this vulnerability is crucial for maintaining the integrity and security of Jenkins instances.
Affected Version(s)
Jenkins Spira Importer Plugin 3.2.2 and earlier
References
CVSS V3.1
Score:
5.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved