Ecosyste.ms: Advisories
An open API service providing security vulnerability metadata for many open source software ecosystems.
Security Advisories: GSA_kwCzR0hTQS1tN3E4LThnNTYtbTc4d833aA
Jenkins Netsparker Enterprise Scan Plugin stored credentials in plain text
Jenkins Netsparker Enterprise Scan Plugin stored API tokens unencrypted in its global configuration file com.netsparker.cloud.plugin.NCScanBuilder.xml
on the Jenkins controller. These API tokens could be viewed by users with access to the Jenkins controller file system.
Netsparker Enterprise Scan Plugin now stores API tokens encrypted.
Permalink: https://github.com/advisories/GHSA-m7q8-8g56-m78wJSON: https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1tN3E4LThnNTYtbTc4d833aA
Source: GitHub Advisory Database
Origin: Unspecified
Severity: Low
Classification: General
Published: almost 2 years ago
Updated: 6 months ago
CVSS Score: 3.3
CVSS vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Identifiers: GHSA-m7q8-8g56-m78w, CVE-2019-10291
References:
- https://nvd.nist.gov/vuln/detail/CVE-2019-10291
- https://jenkins.io/security/advisory/2019-04-03/#SECURITY-1040
- http://www.openwall.com/lists/oss-security/2019/04/12/2
- https://github.com/advisories/GHSA-m7q8-8g56-m78w
Affected Packages
maven:org.jenkins-ci.plugins:netsparker-cloud-scan
Affected Version Ranges: <= 1.1.5Fixed in: 1.1.6