Cleartext transmission of sensitive information in Inedo BuildMaster - CVE-2019-10411
Published: September 26, 2019
Inedo BuildMaster
Detailed vulnerability description
The vulnerability allows a remote attacker to view a password on the target system.
The vulnerability exists due to the affected software stores a password in its global Jenkins configuration form. While the password is stored encrypted on disk, it is transmitted in plain text as part of the configuration form. A remote attacker with ability to intercept network traffic can obtain the password.