#VU22926 Cleartext transmission of sensitive information in QMetry for JIRA - Test Management - CVE-2019-16545
Published: November 22, 2019 / Updated: March 16, 2021
QMetry for JIRA - Test Management
Jenkins
Description
The vulnerability allows a remote attacker to gain access to sensitive information.
The vulnerability exists due to affected plugin transmits credentials in its configuration in plain text as part of job configuration forms. A remote attacker with ability to intercept network traffic can obtain this credential.