QID 995738
Date Published: 2023-10-30
QID 995738: Java (Maven) Security Update for org.jenkins-ci.plugins:youtrack-plugin (GHSA-c7p6-x2p3-3wph)
Jenkins youtrack-plugin Plugin stored credentials unencrypted in its global configuration file org.jenkinsci.plugins.youtrack.YouTrackProjectProperty.xml on the Jenkins controller. These credentials could be viewed by users with access to the Jenkins controller file system.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-c7p6-x2p3-3wph for updates and patch information.
Vendor References
- GHSA-c7p6-x2p3-3wph -
github.com/advisories/GHSA-c7p6-x2p3-3wph
CVEs related to QID 995738
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-c7p6-x2p3-3wph | org.jenkins-ci.plugins:youtrack-plugin |
|