GHSA-3g2g-rcm6-rrq2

Suggest an improvement
Source
https://github.com/advisories/GHSA-3g2g-rcm6-rrq2
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/01/GHSA-3g2g-rcm6-rrq2/GHSA-3g2g-rcm6-rrq2.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-3g2g-rcm6-rrq2
Aliases
  • CVE-2023-24440
Published
2023-01-26T21:30:18Z
Modified
2023-11-08T04:11:45.648178Z
Severity
  • 5.5 (Medium) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N CVSS Calculator
Summary
Cleartext Transmission of Sensitive Information in Jenkins JIRA Pipeline Steps Plugin
Details

Jenkins JIRA Pipeline Steps Plugin 2.0.165.v8846cf59f3db and earlier transmits the private key in plain text as part of the global Jenkins configuration form, potentially resulting in their exposure.

Database specific
{
    "nvd_published_at": "2023-01-26T21:18:00Z",
    "github_reviewed_at": "2023-01-27T01:19:05Z",
    "severity": "MODERATE",
    "github_reviewed": true,
    "cwe_ids": [
        "CWE-319"
    ]
}
References

Affected packages

Maven / org.jenkins-ci.plugins:jira-steps

Package

Name
org.jenkins-ci.plugins:jira-steps
View open source insights on deps.dev
Purl
pkg:maven/org.jenkins-ci.plugins/jira-steps

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Last affected
2.0.165.v8846cf59f3db

Affected versions

1.*

1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.2.5
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.5.0
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.6.0

2.*

2.0.138.vcd973dcde9f6
2.0.141.vd0c6e6dc83f0
2.0.163.vc35a_8a_5a_ef4f
2.0.165.v8846cf59f3db