Insecure Storage of Authentication Tokens in Jenkins PaaSLane Estimate Plugin by Jenkins
CVE-2023-50776
4.3MEDIUM
Key Information:
- Vendor
Jenkins
- Vendor
- CVE Published:
- 13 December 2023
What is CVE-2023-50776?
The Jenkins PaaSLane Estimate Plugin prior to version 1.0.4 insecurely stores authentication tokens in plain text within the job config.xml files on the Jenkins controller. This misconfiguration allows users with Item/Extended Read permissions or those with file system access to potentially expose sensitive authentication tokens. Users are recommended to upgrade to the latest version to mitigate the risk associated with this vulnerability.
Affected Version(s)
Jenkins PaaSLane Estimate Plugin 0 <= 1.0.4