#VU18073 Cleartext storage of sensitive information in Codebeamer Test Results Trend Updater
Published: March 25, 2019
Codebeamer Test Results Trend Updater
Jenkins
Description
The disclosed vulnerability allows a local user to gain access to sensitive information.
The vulnerability exists due to application stores username and password in its configuration unencrypted in jobs' config.xml files on the Jenkins master.. A local user with with Extended Read permission or access to the master filesystem can obtain the password.