PT-2019-14697 · Jenkins · Jenkins Anchore Container Image Scanner Plugin+1

·

CVE-2019-16542

·

Publicado

2019-11-21

·

Atualizado

2023-10-25

CVSS v3.1

6.5

Média

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Jenkins Anchore Container Image Scanner Plugin versions 1.0.19 and earlier
Description The plugin stores credentials unencrypted in job config.xml files on the Jenkins master, allowing users with Extended Read permission or access to the master file system to view them. The stored credential was a service password for the Anchore.io service. Since the affected functionality has been deprecated and the Anchore.io service was shut down in late 2018, the affected feature has been removed.
Recommendations For Jenkins Anchore Container Image Scanner Plugin versions 1.0.19 and earlier, consider removing or disabling the affected feature to minimize potential risks, as the functionality has been deprecated and the related service is no longer available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Insufficiently Protected Credentials

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2019-16542
GHSA-JG29-C2QJ-WPM3

Produtos afetados

Jenkins
Jenkins Anchore Container Image Scanner Plugin