QID 996799
Date Published: 2024-01-23
QID 996799: Java (Maven) Security Update for org.jenkins-ci.plugins:audit2db (GHSA-vv6p-63g8-m8fw)
Jenkins Audit to Database Plugin stores database credentials unencrypted in its global configuration file audit2db.xml on the Jenkins controller. These credentials can be viewed by users with access to the Jenkins controller file system.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-vv6p-63g8-m8fw for updates and patch information.
Vendor References
- GHSA-vv6p-63g8-m8fw -
github.com/advisories/GHSA-vv6p-63g8-m8fw
CVEs related to QID 996799
Software Advisories
| Advisory ID | Software | Component | Link |
|---|