Jenkins Serena SRA Deploy Plugin stores credentials unencrypted in its global configuration file com.urbancode.ds.jenkins.plugins.serenarapublisher.UrbanDeployPublisher.xml
on the Jenkins controller. These credentials can be viewed by users with access to the Jenkins controller file system.
{ "github_reviewed_at": "2023-10-26T16:53:15Z", "cwe_ids": [ "CWE-522" ], "nvd_published_at": "2019-04-04T16:29:00Z", "severity": "LOW", "github_reviewed": true }