SB2019032506 - Information disclosure in Jenkins ECS Publisher plugin



SB2019032506 - Information disclosure in Jenkins ECS Publisher plugin

Published: March 25, 2019

Security Bulletin ID SB2019032506
Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Local access
Highest impact Data manipulation

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Cleartext storage of sensitive information (CVE-ID: N/A)

The disclosed vulnerability allows a local user to gain access to sensitive information.

The vulnerability exists due to application stores the API token unencrypted in jobs' config.xml files and its global configuration file on the Jenkins master. A user with Extended Read permission or access to the master file system can obtain to the API token.


Remediation

Install update from vendor's website.