Insecure Credential Storage Affecting org.jenkins-ci.plugins:jira-ext package, versions [,0.9)


Severity

Recommended
0.0
low
0
10

CVSS assessment made by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.17% (55th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-JAVA-ORGJENKINSCIPLUGINS-174462
  • published18 Apr 2019
  • disclosed18 Apr 2019
  • creditViktor Gazdag

Introduced: 18 Apr 2019

CVE-2019-10302  (opens in a new tab)
CWE-255  (opens in a new tab)

How to fix?

Upgrade org.jenkins-ci.plugins:jira-ext to version 0.9 or higher.

Overview

org.jenkins-ci.plugins:jira-ext is a plugin for Jenkins CI to update JIRA tickets in an extensible way.

Affected versions of this package have Insecure Credential Storage. The plugin stores credentials unencrypted in its global configuration file hudson.plugins.jira.JiraProjectProperty.xml. They could be viewed by users with access to the master file system.

CVSS Scores

version 3.1