PT-2019-11757 · Jenkins · Jenkins Maven Release Plugin+1

David Fiser

·

Published

2019-07-31

·

Updated

2023-10-25

·

CVE-2019-10361

CVSS v3.1

3.3

Low

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Jenkins Maven Release Plugin versions 0.14.0 and earlier
Description The issue concerns the storage of credentials in an unencrypted manner on the Jenkins master, allowing users with access to the master file system to view them. Specifically, the credentials were stored in the global configuration file org.jvnet.hudson.plugins.m2release.M2ReleaseBuildWrapper.xml on the Jenkins controller. This could lead to information disclosure. The credentials are now stored encrypted.
Recommendations For Jenkins Maven Release Plugin versions 0.14.0 and earlier, update the plugin to a version that stores credentials encrypted, as the current version stores credentials unencrypted in its global configuration file.

Fix

Insufficiently Protected Credentials

Weakness Enumeration

Related Identifiers

CVE-2019-10361
GHSA-VWX8-QPQH-QWM9
ZDI-19-835

Affected Products

Jenkins
Jenkins Maven Release Plugin