SB2019030705 - Cleartext storage of passwords in Jenkins AppDynamics Dashboard plugin



SB2019030705 - Cleartext storage of passwords in Jenkins AppDynamics Dashboard plugin

Published: March 7, 2019

Security Bulletin ID SB2019030705
Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Local access
Highest impact Information disclosure

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Cleartext storage of sensitive information (CVE-ID: N/A)

The vulnerability allows a local user to gain access to sensitive information.

The vulnerability exists due to the AppDynamics Dashboard Plugin stores username and password in its configuration unencrypted in jobs' config.xml files on the Jenkins master. A local user can view credentials of other users.

Remediation

Install update from vendor's website.