Cleartext storage of sensitive information in Consul KV Builder - CVE-2023-30530
Published: April 13, 2023
Consul KV Builder
Jenkins
Description
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to the affected plugin stores the HashiCorp Consul ACL Token unencrypted in its global configuration file org.jenkinsci.plugins.consulkv.GlobalConsulConfig.xml on the Jenkins controller as part of its configuration. A remote user can gain access to this token.