Ecosyste.ms: Advisories
An open API service providing security vulnerability metadata for many open source software ecosystems.
Security Advisories: GSA_kwCzR0hTQS1qcm1mLXhocjYtMzQyOM4AAiOG
Jenkins SourceGear Vault plugin transmits credentials in plain text
Jenkins SourceGear Vault Plugin transmits configured credentials in plain text as part of job configuration forms, potentially resulting in their exposure. As of the publication of the advisory, there are no patches and the plugin is unmaintained.
Permalink: https://github.com/advisories/GHSA-jrmf-xhr6-3428JSON: https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1qcm1mLXhocjYtMzQyOM4AAiOG
Source: GitHub Advisory Database
Origin: Unspecified
Severity: High
Classification: General
Published: over 1 year ago
Updated: 10 months ago
CVSS Score: 7.5
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Identifiers: GHSA-jrmf-xhr6-3428, CVE-2019-10435
References:
- https://nvd.nist.gov/vuln/detail/CVE-2019-10435
- https://jenkins.io/security/advisory/2019-10-01/#SECURITY-1524
- http://www.openwall.com/lists/oss-security/2019/10/01/2
- https://github.com/advisories/GHSA-jrmf-xhr6-3428
Affected Packages
maven:org.jenkins-ci.plugins:vault-scm-plugin
Versions: <= 1.1.1No known fixed version