Unencrypted Credential Storage in Jenkins Spira Importer Plugin by CloudBees
CVE-2019-16543

5.5MEDIUM

Key Information:

Vendor
Jenkins
Vendor
CVE Published:
21 November 2019

Summary

The Jenkins Spira Importer Plugin versions prior to 3.2.2 store user credentials without encryption in the global configuration file of the Jenkins master. This security flaw allows users with access to the master file system to view these sensitive credentials, potentially leading to unauthorized access and exploitation. Mitigating this vulnerability is crucial for maintaining the integrity and security of Jenkins instances.

Affected Version(s)

Jenkins Spira Importer Plugin 3.2.2 and earlier

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.