Jenkins Build-Publisher plugin version 1.21 and earlier stores credentials to other Jenkins instances in the file hudson.plugins.build_publisher.BuildPublisher.xml in the Jenkins master home directory. These credentials were stored unencrypted, allowing anyone with local file system access to access them. Additionally, the credentials were also transmitted in plain text as part of the configuration form. This could result in exposure of the credentials through browser extensions, cross-site scripting vulnerabilities, and similar situations.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2018-01-26T02:00:00
Updated: 2024-08-05T22:00:41.187Z
Reserved: 2017-11-29T00:00:00
Link: CVE-2017-1000387
Vulnrichment
No data.
NVD
Status : Modified
Published: 2018-01-26T02:29:00.330
Modified: 2024-11-21T03:04:36.817
Link: CVE-2017-1000387
Redhat
No data.