GHSA-wphq-j78p-fhgp
LOWCVE-2020-2239Parameterized Remote Trigger Plugin 3.1.3 and earlier stores a secret unencrypted in its global configuration file org.jenkinsci.plugins.ParameterizedRemoteTrigger.RemoteBuildConfiguration.xml on the Jenkins controller as part of its configuration. This secret can be viewed by attackers with access to the Jenkins controller file system.
- Affected
- <= 3.1.3
- Fixed in
- 3.1.4
- Weakness
- CWE-256
- Published
- 2022-05-24
- Source
- github