Impact
The plugin stores authentication tokens in plain text within job configuration files. A user with Item/Extended Read permission or anyone able to read the Jenkins controller file system can view these tokens. Because the tokens are not protected by encryption or secure storage, an attacker may obtain valid credentials that could grant further access to Jenkins or downstream systems, constituting a confidentiality compromise.
Affected Systems
Jenkins Project Jenkins Parameterized Remote Trigger Plugin 3.2.2 and any earlier release. This vulnerability exists on Jenkins controllers where a job’s config.xml file is stored and accessible.
Risk and Exploitability
The CVSS score is 4.3, indicating a moderate impact. The EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog. The likely attack path is local or privileged access from a user who has at least Item/Extended Read rights, allowing them to read the configuration file or the file system to retrieve the unencrypted tokens.
OpenCVE Enrichment