Vulnerability GHSA-mhq6-h9m7-wq8c
Low Risk
LOW RISK
CVSS Score: 3.3
Score Range: < 4.0
Low severity vulnerabilities (CVSS < 4.0). Hygiene issues that can accumulate but pose lower immediate risk.
4 years ago
May 24, 2022 at 04:56 PM UTC
Jenkins Assembla Plugin has Insufficiently Protected Credentials
1.2.0 - 1.4.0
1.2.0 - 1.4.0
Summary
Jenkins Assembla Plugin has Insufficiently Protected Credentials
Details
Assembla Plugin stores the Assembla password unencrypted in its global configuration file jenkins.plugin.assembla.AssemblaProjectProperty.xml on the Jenkins controller. This password can be viewed by users with access to the Jenkins controller file system.
As of publication of this advisory, there is no fix.
Related Vulnerabilities
Other vulnerabilities affecting the same packages
High Risk
3 months ago
Jenkins Assembla Plugin has an XXE vulnerability
1.2.0 - 1.4.0 GHSA-2q27-6p2h-q6r3
1.2.0 - 1.4.0 GHSA-2q27-6p2h-q6r3
Medium Risk
3 months ago
Jenkins Assembla Plugin has a missing permission check
1.2.0 - 1.4.0 GHSA-2r5w-jh6g-8hff
1.2.0 - 1.4.0 GHSA-2r5w-jh6g-8hff
Medium Risk
3 months ago
Jenkins Assembla Plugin has a cross-site request forgery (CSRF) vulnerability
1.2.0 - 1.4.0 GHSA-429r-3j78-2pxm
1.2.0 - 1.4.0 GHSA-429r-3j78-2pxm
Impacted packages
Timeline
Published
4 years ago
May 24, 2022 at 04:56 PM UTC
Last Modified
2 years ago
November 08, 2023 at 04:00 AM UTC