Jenkins Azure PublisherSettings Credentials Plugin stored credentials in plain text
Low severity
GitHub Reviewed
Published
May 24, 2022
to the GitHub Advisory Database
•
Updated Oct 26, 2023
Package
Affected versions
< 1.5
Patched versions
1.5
Description
Published by the National Vulnerability Database
Apr 18, 2019
Published to the GitHub Advisory Database
May 24, 2022
Last updated
Oct 26, 2023
Reviewed
Oct 26, 2023
Jenkins Azure PublisherSettings Credentials Plugin stored the service management certificate unencrypted in credentials.xml on the Jenkins controller. These credentials could be viewed by users with access to the Jenkins controller file system.
Azure PublisherSettings Credentials Plugin has been deprecated. Azure PublisherSettings Credentials Plugin 1.5 no longer provides any user features and we recommend the plugin be uninstalled.
References