A exposure of sensitive information vulnerability exists in Jenkins z/OS Connector Plugin 1.2.6.1 and earlier in SCLMSCM.java that allows an attacker with local file system access or control of a Jenkins administrator's web browser (e.g. malicious extension) to retrieve the configured password. IBM z/OS Connector Plugin 2.0.0 and newer integrates with Credentials Plugin, no longer storing credentials itself.
{ "nvd_published_at": "2018-06-26T17:29:00Z", "github_reviewed_at": "2022-12-07T18:14:25Z", "severity": "LOW", "github_reviewed": true, "cwe_ids": [ "CWE-522" ] }