Jenkins Bitbucket OAuth Plugin 0.9 and earlier stored credentials unencrypted in the global config.xml configuration file on the Jenkins master where they could be viewed by users with access to the master file system.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: jenkins
Published: 2019-10-23T12:45:38
Updated: 2024-08-04T22:24:18.540Z
Reserved: 2019-03-29T00:00:00
Link: CVE-2019-10460
Vulnrichment
No data.
NVD
Status : Modified
Published: 2019-10-23T13:15:10.393
Modified: 2023-10-25T18:16:24.883
Link: CVE-2019-10460
Redhat
No data.