QID 996816

Date Published: 2024-01-23

QID 996816: Java (Maven) Security Update for org.jenkins-ci.plugins:aqua-security-scanner (GHSA-3j3v-7f8f-v2xp)

Jenkins Aqua Security Scanner Plugin stores credentials unencrypted in its global configuration file org.jenkinsci.plugins.aquadockerscannerbuildstep.AquaDockerScannerBuilder.xml on the Jenkins controller. These credentials can be viewed by users with access to the Jenkins controller file system.

Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.

  • CVSS V3 rated as Critical - 8.8 severity.
  • CVSS V2 rated as Medium - 4 severity.
  • Solution
    Refer to Github security advisory GHSA-3j3v-7f8f-v2xp for updates and patch information.
    Vendor References

    CVEs related to QID 996816

    Software Advisories
    Advisory ID Software Component Link
    GHSA-3j3v-7f8f-v2xp org.jenkins-ci.plugins:aqua-security-scanner URL Logo github.com/advisories/GHSA-3j3v-7f8f-v2xp