Bug 2294463 (CVE-2024-39459) - CVE-2024-39459 jenkins: plain-credentials: Improper storage of credentials
Summary: CVE-2024-39459 jenkins: plain-credentials: Improper storage of credentials
Keywords:
Status: NEW
Alias: CVE-2024-39459
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks: 2294461
TreeView+ depends on / blocked
 
Reported: 2024-06-27 03:02 UTC by Patrick Del Bello
Modified: 2024-11-30 08:27 UTC (History)
8 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description Patrick Del Bello 2024-06-27 03:02:40 UTC
In rare cases Jenkins Plain Credentials Plugin 182.v468b_97b_9dcb_8 and earlier stores secret file credentials unencrypted (only Base64 encoded) on the Jenkins controller file system, where they can be viewed by users with access to the Jenkins controller file system (global credentials) or with Item/Extended Read permission (folder-scoped credentials).

http://www.openwall.com/lists/oss-security/2024/06/26/2
https://www.jenkins.io/security/advisory/2024-06-26/#SECURITY-2495


Note You need to log in before you can comment on or make changes to this bug.