A vulnerability in Jenkins PRQA Plugin 3.1.0 and earlier allows attackers with local file system access to the Jenkins home directory to obtain the unencrypted password from the plugin configuration.
The product does not encrypt sensitive or critical information before storage or transmission.
Link | Tags |
---|---|
http://www.openwall.com/lists/oss-security/2019/03/28/2 | third party advisory mailing list |
http://www.securityfocus.com/bid/107628 | vdb entry third party advisory |
https://jenkins.io/security/advisory/2019-03-25/#SECURITY-1089 | vendor advisory |