GHSA-3p8r-p4q5-mc44
MODERATECVE-2019-10416Violation Comments to GitLab Plugin stored API tokens unencrypted in job config.xml files and its global configuration file org.jenkinsci.plugins.jvctgl.ViolationsToGitLabGlobalConfiguration.xml on the Jenkins controller. These credentials could be viewed by users with Extended Read permission, or access to the Jenkins controller file system.
- Affected
- < 2.29
- Fixed in
- 2.29
- Weakness
- CWE-522
- Published
- 2022-05-24
- Source
- github