Loading HuntDB...

GHSA-8g6v-g8qc-5w7j

GitHub Security Advisory

Token stored in plain text by DigitalOcean Plugin

✓ GitHub Reviewed LOW Has CVE

Advisory Details

Jenkins DigitalOcean Plugin 1.1 and earlier stores a token unencrypted in the global config.xml file on the Jenkins master where it can be viewed by users with access to the master file system.

Affected Packages

Maven com.dubture.jenkins:digitalocean-plugin
Affected versions: 0 (fixed in 1.2.0)

Related CVEs

Key Information

GHSA ID
GHSA-8g6v-g8qc-5w7j
Published
May 24, 2022 5:08 PM
Last Modified
January 9, 2023 7:42 PM
CVSS Score
2.5 /10
Primary Ecosystem
Maven
Primary Package
com.dubture.jenkins:digitalocean-plugin
GitHub Reviewed
✓ Yes

Dataset

Last updated: August 27, 2025 6:31 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.