#VU49544 Cleartext storage of sensitive information in Bumblebee HP ALM - CVE-2021-21614
Published: January 13, 2021 / Updated: January 14, 2021
Bumblebee HP ALM
Jenkins
Description
The vulnerability allows a local user to view the password on the target system.
The vulnerability exists due to the affected software stores credentials unencrypted in its global configuration file "com.agiletestware.bumblebee.BumblebeeGlobalConfig.xml" on the Jenkins controller. A local user with access to the Jenkins controller file system can obtain credentials.