Password stored in a recoverable format by Jenkins OpenId Connect Authentication Plugin
Moderate severity
GitHub Reviewed
Published
Dec 13, 2023
to the GitHub Advisory Database
•
Updated Nov 15, 2024
Package
Affected versions
< 4.229.vf736b
Patched versions
4.229.vf736b
Description
Published by the National Vulnerability Database
Dec 13, 2023
Published to the GitHub Advisory Database
Dec 13, 2023
Reviewed
Dec 13, 2023
Last updated
Nov 15, 2024
Jenkins OpenId Connect Authentication Plugin stores a password of a local user account used as an anti-lockout feature in a recoverable format, allowing attackers with access to the Jenkins controller file system to recover the plain text password of that account, likely gaining administrator access to Jenkins.
References