PT-2023-22751 · Jenkins · Jenkins Report Portal Plugin+1

Cc Bomber

+1

·

Published

2023-04-12

·

Updated

2023-04-20

·

CVE-2023-30523

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Jenkins Report Portal Plugin versions 0.5 and earlier
Description The Jenkins Report Portal Plugin stores ReportPortal access tokens unencrypted in job config.xml files on the Jenkins controller as part of its configuration. These tokens can be viewed by users with Item/Extended Read permission or access to the Jenkins controller file system. The configuration form does not mask these tokens, increasing the potential for attackers to observe and capture them.
Recommendations For Jenkins Report Portal Plugin versions 0.5 and earlier, consider restricting access to the Jenkins controller file system and limiting Item/Extended Read permission to minimize the risk of exploitation. As a temporary workaround, consider masking ReportPortal access tokens in the configuration form until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Missing Encryption of Sensitive Data

Cleartext Storage of Sensitive Information

Weakness Enumeration

Related Identifiers

CVE-2023-30523
GHSA-QGW9-VGRF-H723

Affected Products

Jenkins
Jenkins Report Portal Plugin