Vulnerability GHSA-j4ph-wp3c-c37w
Medium Risk
MEDIUM RISK
CVSS Score: 4.3
Score Range: 4.0–6.9
Medium severity vulnerabilities (CVSS 4.0–6.9). Important issues that meaningfully reduce security confidence.
3 months ago
June 24, 2026 at 03:31 PM UTC
Jenkins FitNesse Plugin stores passwords unencrypted
1.5.0 - 1.16.0 and 1.24.0 and 1.26.0 - 1.28.0 and 1.30.0 - 1.31.0 and 1.33.0 - 1.36.0
1.5.0 - 1.16.0 and 1.24.0 and 1.26.0 - 1.28.0 and 1.30.0 - 1.31.0 and 1.33.0 - 1.36.0
Summary
Jenkins FitNesse Plugin stores passwords unencrypted
Details
Jenkins FitNesse Plugin 1.36 and earlier stores passwords unencrypted in job config.xml files on the Jenkins controller as part of its configuration.
These passwords can be viewed by users with Item/Extended Read permission or access to the Jenkins controller file system.
As of publication of this advisory, there is no fix.
Related Vulnerabilities
Other vulnerabilities affecting the same packages
Medium Risk
4 years ago
Stored XSS vulnerability in Jenkins FitNesse Plugin
1.5.0 - 1.16.0 and 1.24.0 and 1.26.0 - 1.28.0 and 1.30.0 - 1.31.0 GHSA-f6vx-3fq6-hxm8
1.5.0 - 1.16.0 and 1.24.0 and 1.26.0 - 1.28.0 and 1.30.0 - 1.31.0 GHSA-f6vx-3fq6-hxm8
High Risk
4 years ago
XXE vulnerability in FitNesse Plugin
1.5.0 - 1.16.0 and 1.24.0 and 1.26.0 - 1.28.0 and 1.30.0 GHSA-c3cg-mv5w-cvw8
1.5.0 - 1.16.0 and 1.24.0 and 1.26.0 - 1.28.0 and 1.30.0 GHSA-c3cg-mv5w-cvw8
Impacted packages
Timeline
Published
3 months ago
June 24, 2026 at 03:31 PM UTC
Last Modified
2 days ago
September 25, 2026 at 08:00 PM UTC