GHSA-36j8-f33j-vjwq
GitHub Security Advisory
Passwords stored in plain text by Jenkins hpe-network-virtualization plugin
✓ GitHub Reviewed
LOW
Has CVE
Advisory Details
hpe-network-virtualization Plugin 1.0 stores passwords unencrypted in its global configuration file `org.jenkinsci.plugins.nvemulation.plugin.NvEmulationBuilder.xml` on the Jenkins controller as part of its configuration.
These passwords can be viewed by users with access to the Jenkins controller file system.
Affected Packages
Maven
org.jenkins-ci.plugins:hpe-network-virtualization
Related CVEs
Key Information
2.5
/10
Dataset
Last updated: August 27, 2025 6:31 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.