Loading HuntDB...

GHSA-f6g8-pxvp-9328

GitHub Security Advisory

Jenkins Inedo ProGet Plugin Plugin has Cleartext Transmission of Sensitive Information

✓ GitHub Reviewed LOW Has CVE

Advisory Details

Inedo ProGet Plugin Plugin stores a service password in its global Jenkins configuration.

While the password is stored encrypted on disk, it was transmitted in plain text as part of the configuration form. This could result in exposure of the password through browser extensions, cross-site scripting vulnerabilities, and similar situations.

Inedo ProGet Plugin Plugin now encrypts the password transmitted to administrators viewing the global configuration form.

Affected Packages

Maven com.inedo.proget:inedo-proget
Affected versions: 0 (fixed in 1.3)

Related CVEs

Key Information

GHSA ID
GHSA-f6g8-pxvp-9328
Published
May 24, 2022 4:56 PM
Last Modified
February 23, 2023 8:32 PM
CVSS Score
2.5 /10
Primary Ecosystem
Maven
Primary Package
com.inedo.proget:inedo-proget
GitHub Reviewed
✓ Yes

Dataset

Last updated: August 27, 2025 6:31 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.