PT-2021-14657 · Jenkins · Jenkins Bumblebee Hp Alm Plugin+1

S0Nnguy3N

+1

·

Published

2021-01-13

·

Updated

2023-10-25

·

CVE-2021-21614

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Jenkins Bumblebee HP ALM Plugin versions 4.1.5 and earlier
Description The issue concerns the storage of credentials in an unencrypted manner within the global configuration file on the Jenkins controller. Specifically, the credentials are stored in the com.agiletestware.bumblebee.BumblebeeGlobalConfig.xml file. Users with access to the Jenkins controller file system can view these credentials. It is noted that credentials are stored encrypted in version 4.1.6 once the configuration is saved again.
Recommendations For Jenkins Bumblebee HP ALM Plugin versions 4.1.5 and earlier, update to version 4.1.6 or later to ensure credentials are stored encrypted. As a temporary workaround, consider restricting access to the Jenkins controller file system to minimize the risk of credential exposure.

Fix

Insufficiently Protected Credentials

Weakness Enumeration

Related Identifiers

CVE-2021-21614
GHSA-8V72-QR3H-C6RV

Affected Products

Jenkins
Jenkins Bumblebee Hp Alm Plugin