QID 995952
Date Published: 2023-11-20
QID 995952: Java (Maven) Security Update for org.jenkins-ci.plugins.m2release:m2release (GHSA-vwx8-qpqh-qwm9)
Jenkins Maven Release Plug-in Plugin stored credentials unencrypted in its global configuration file org.jvnet.hudson.plugins.m2release.M2ReleaseBuildWrapper.xml on the Jenkins controller. These credentials could be viewed by users with access to the Jenkins controller file system.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-vwx8-qpqh-qwm9 for updates and patch information.
Vendor References
- GHSA-vwx8-qpqh-qwm9 -
github.com/advisories/GHSA-vwx8-qpqh-qwm9
CVEs related to QID 995952
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-vwx8-qpqh-qwm9 | org.jenkins-ci.plugins.m2release:m2release |
|