Jenkins QMetry for JIRA Plugin shows plain text password in configuration form
Low severity
GitHub Reviewed
Published
May 24, 2022
to the GitHub Advisory Database
•
Updated Oct 27, 2023
Package
Affected versions
<= 1.13
Patched versions
1.14.0
Description
Published by the National Vulnerability Database
Nov 21, 2019
Published to the GitHub Advisory Database
May 24, 2022
Last updated
Oct 27, 2023
Reviewed
Oct 27, 2023
Jenkins QMetry for JIRA - Test Management Plugin stores a credential as part of its post-build step configuration.
While the password is stored encrypted on disk since QMetry for JIRA - Test Management Plugin 1.13, it is transmitted in plain text as part of the configuration form. This can result in exposure of the password through browser extensions, cross-site scripting vulnerabilities, and similar situations.
References