cbcvebase.
CVE-2021-21612
published 2021-01-13

CVE-2021-21612: Jenkins TraceTronic ECU-TEST Plugin 2.23.1 and earlier stores credentials unencrypted in its global configuration file on the Jenkins controller where they can…

medium5.5CVSS 3.1
AVLACLPRLUINSUCHINAN
Jenkins TraceTronic ECU-TEST Plugin 2.23.1 and earlier stores credentials unencrypted in its global configuration file on the Jenkins controller where they can be viewed by users with access to the Jenkins controller file system.

Affected

8 ranges
VendorProductVersion rangeFixed in
jenkinsanything_goes_formatter_plugin
jenkinsbumblebee_hp_alm_plugin
jenkinsjenkins_core
jenkinsjenkins_lts
jenkinsjenkins_weekly
jenkinstics_plugin
jenkinstracetronic_ecu-test<= 2.23.1
jenkins_projectjenkins_tracetronic_ecu-test_pluginunspecified – 2.23.1