GHSA-3cpq-rw36-cppv

Suggest an improvement
Source
https://github.com/advisories/GHSA-3cpq-rw36-cppv
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/06/GHSA-3cpq-rw36-cppv/GHSA-3cpq-rw36-cppv.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-3cpq-rw36-cppv
Aliases
  • CVE-2024-39459
Published
2024-06-26T18:30:28Z
Modified
2024-11-01T20:11:35.521524Z
Severity
  • 4.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N CVSS Calculator
Summary
Secret file credentials stored unencrypted in rare cases by Plain Credentials Plugin
Details

When creating secret file credentials Plain Credentials Plugin 182.v468b97b9dcb_8 and earlier attempts to decrypt the content of the file to check if it constitutes a valid encrypted secret. In rare cases the file content matches the expected format of an encrypted secret, and the file content will be stored unencrypted (only Base64 encoded) on the Jenkins controller file system.

These credentials can be viewed by users with access to the Jenkins controller file system (global credentials) or with Item/Extended Read permission (folder-scoped credentials).

Plain Credentials Plugin 183.vade8f1dd5a2b_ no longer attempts to decrypt the content of the file when creating secret file credentials.

Database specific
{
    "nvd_published_at": "2024-06-26T17:15:27Z",
    "cwe_ids": [
        "CWE-319",
        "CWE-922"
    ],
    "severity": "MODERATE",
    "github_reviewed": true,
    "github_reviewed_at": "2024-06-26T20:07:12Z"
}
References

Affected packages

Maven / org.jenkins-ci.plugins:plain-credentials

Package

Name
org.jenkins-ci.plugins:plain-credentials
View open source insights on deps.dev
Purl
pkg:maven/org.jenkins-ci.plugins/plain-credentials

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
183.va

Affected versions

1.*

1.0-beta-1
1.0-beta-2
1.0-beta-3
1.0-beta-4
1.0
1.1
1.2
1.3
1.4
1.5
1.6
1.7
1.8

139.*

139.ved2b_9cf7587b

143.*

143.v1b_df8b_d3b_e48

177.*

177.vb_231f25527e7

179.*

179.vc5cb_98f6db_38

182.*

182.v468b_97b_9dcb_8