A exposure of sensitive information vulnerability exists in Jenkins z/OS Connector Plugin 1.2.6.1 and earlier in SCLMSCM.java that allows an attacker with local file system access or control of a Jenkins administrator's web browser (e.g. malicious extension) to retrieve the configured password. IBM z/OS Connector Plugin 2.0.0 and newer integrates with Credentials Plugin, no longer storing credentials itself.
{
"github_reviewed": true,
"cwe_ids": [
"CWE-522"
],
"github_reviewed_at": "2022-12-07T18:14:25Z",
"nvd_published_at": "2018-06-26T17:29:00Z",
"severity": "LOW"
}