CVE-2021-21612
published 2021-01-13CVE-2021-21612: Jenkins TraceTronic ECU-TEST Plugin 2.23.1 and earlier stores credentials unencrypted in its global configuration file on the Jenkins controller where they can…
medium5.5CVSS 3.1
AVLACLPRLUINSUCHINAN
Jenkins TraceTronic ECU-TEST Plugin 2.23.1 and earlier stores credentials unencrypted in its global configuration file on the Jenkins controller where they can be viewed by users with access to the Jenkins controller file system.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| jenkins | anything_goes_formatter_plugin | — | — |
| jenkins | bumblebee_hp_alm_plugin | — | — |
| jenkins | jenkins_core | — | — |
| jenkins | jenkins_lts | — | — |
| jenkins | jenkins_weekly | — | — |
| jenkins | tics_plugin | — | — |
| jenkins | tracetronic_ecu-test | <= 2.23.1 | — |
| jenkins_project | jenkins_tracetronic_ecu-test_plugin | unspecified – 2.23.1 | — |