Jenkins QMetry for JIRA - Test Management Plugin stores a credential as part of its post-build step configuration.
While the password is stored encrypted on disk since QMetry for JIRA - Test Management Plugin 1.13, it is transmitted in plain text as part of the configuration form. This can result in exposure of the password through browser extensions, cross-site scripting vulnerabilities, and similar situations.
{ "nvd_published_at": "2019-11-21T15:15:00Z", "cwe_ids": [ "CWE-319" ], "severity": "LOW", "github_reviewed": true, "github_reviewed_at": "2023-10-27T17:39:59Z" }