Cleartext storage of sensitive information in Codebeamer Test Results Trend Updater - #VU18073
Published: March 25, 2019
Codebeamer Test Results Trend Updater
Detailed vulnerability description
The disclosed vulnerability allows a local user to gain access to sensitive information.
The vulnerability exists due to application stores username and password in its configuration unencrypted in jobs' config.xml files on the Jenkins master.. A local user with with Extended Read permission or access to the master filesystem can obtain the password.