GHSA-5722-v5wc-x7h8
LOWCVE-2019-1003070Jenkins veracode-scanner Plugin stores credentials unencrypted in its global configuration file org.jenkinsci.plugins.veracodescanner.VeracodeNotifier.xml on the Jenkins controller. These credentials can be viewed by users with access to the Jenkins controller file system.
- Affected
- <= 1.6
- Fixed in
- not stated
- Weakness
- CWE-311
- Published
- 2022-05-13
- Source
- github