PT-2021-14657 · Jenkins · Jenkins Bumblebee Hp Alm Plugin+1
S0Nnguy3N
+1
·
Published
2021-01-13
·
Updated
2023-10-25
·
CVE-2021-21614
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Jenkins Bumblebee HP ALM Plugin versions 4.1.5 and earlier
Description
The issue concerns the storage of credentials in an unencrypted manner within the global configuration file on the Jenkins controller. Specifically, the credentials are stored in the
com.agiletestware.bumblebee.BumblebeeGlobalConfig.xml file. Users with access to the Jenkins controller file system can view these credentials. It is noted that credentials are stored encrypted in version 4.1.6 once the configuration is saved again.Recommendations
For Jenkins Bumblebee HP ALM Plugin versions 4.1.5 and earlier, update to version 4.1.6 or later to ensure credentials are stored encrypted. As a temporary workaround, consider restricting access to the Jenkins controller file system to minimize the risk of credential exposure.
Fix
Insufficiently Protected Credentials
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Jenkins
Jenkins Bumblebee Hp Alm Plugin