#VU21977 Cleartext storage of sensitive information in NeoLoad - CVE-2019-10440
Published: October 21, 2019 / Updated: October 22, 2019
NeoLoad
Jenkins
Description
The vulnerability allows a remote user to view the password on the target system.
The vulnerability exists due to the affected software stores credentials unencrypted in its global configuration file "org.jenkinsci.plugins.neoload.integration.NeoGlobalConfig.xml" and in job "config.xml" files on the Jenkins master. A remote authenticated user with Extended Read permission or access to the master file system can obtain credentials.