SB2019032506 - Information disclosure in Jenkins ECS Publisher plugin
Published: March 25, 2019
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Cleartext storage of sensitive information (CVE-ID: N/A)
The disclosed vulnerability allows a local user to gain access to sensitive information.
The vulnerability exists due to application stores the API token unencrypted in jobs' config.xml files and its global configuration file on the Jenkins master. A user with Extended Read permission or access to the master file system can obtain to the API token.
Remediation
Install update from vendor's website.