GHSA-56hc-wf49-2h96
GitHub Security Advisory
Plaintext Storage of a Password in Jenkins Deployment Dashboard Plugin
✓ GitHub Reviewed
LOW
Has CVE
Advisory Details
Deployment Dashboard Plugin 1.0.10 and earlier stores a password unencrypted in its global configuration file `de.codecentric.jenkins.dashboard.DashboardView.xml` on the Jenkins controller as part of its configuration. This password can be viewed by users with access to the Jenkins controller file system.
Affected Packages
Maven
org.jenkins-ci.plugins:ec2-deployment-dashboard
Affected versions:
0
(last affected: 1.0.10)
Related CVEs
Key Information
2.5
/10
Dataset
Last updated: July 4, 2025 6:27 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.