cbcvebase.
CVE-2023-30527
published 2023-04-12

CVE-2023-30527: Jenkins WSO2 Oauth Plugin 1.0 and earlier stores the WSO2 Oauth client secret unencrypted in the global config.xml file on the Jenkins controller where it can…

medium4.3CVSS 3.1
AVNACLPRLUINSUCLINAN
Jenkins WSO2 Oauth Plugin 1.0 and earlier stores the WSO2 Oauth client secret unencrypted in the global config.xml file on the Jenkins controller where it can be viewed by users with access to the Jenkins controller file system.

Affected

16 ranges
VendorProductVersion rangeFixed in
jenkinsassembla_merge_request_builder_plugin
jenkinsazure_key_vault_plugin
jenkinsconsul_kv_builder_plugin
jenkinsdelinea_secret_server_platform_plugin
jenkinsfogbugz_plugin
jenkinsimage_tag_parameter_plugin
jenkinskubernetes_plugin
jenkinslack_of_authentication_mechanism_in_fogbugz_plugin
jenkinslack_of_authentication_mechanism_in_turboscript_plugin
jenkinslucene-search_plugin
jenkinsquay.io_trigger_plugin
jenkinsreport_portal_plugin
jenkinsthycotic_devops_secrets_vault_plugin
jenkinsturboscript_plugin
jenkinswso2_oauth<= 1.0
jenkins_projectjenkins_wso2_oauth_plugin<= 1.0