Loading HuntDB...

GHSA-jjmv-6fv4-85vf

GitHub Security Advisory

Jenkins Data Theorem Mobile Security: CI/CD Plugin has Insufficiently Protected Credentials

✓ GitHub Reviewed MODERATE Has CVE

Advisory Details

Data Theorem Mobile Security: CI/CD Plugin stored a proxy password unencrypted in job `config.xml` files on the Jenkins controller. This password could be viewed by users with Extended Read permission, or access to the Jenkins controller file system.

Data Theorem Mobile Security: CI/CD Plugin now stores the proxy password encrypted. Existing jobs need to have their configuration saved for existing plain text proxy passwords to be overwritten.

Affected Packages

Maven com.datatheorem.mobileappsecurity.jenkins.plugin:datatheorem-mobile-app-security
Affected versions: 0 (fixed in 1.4.0)

Related CVEs

Key Information

GHSA ID
GHSA-jjmv-6fv4-85vf
Published
May 24, 2022 4:56 PM
Last Modified
February 23, 2023 8:31 PM
CVSS Score
5.0 /10
Primary Ecosystem
Maven
Primary Package
com.datatheorem.mobileappsecurity.jenkins.plugin:datatheorem-mobile-app-security
GitHub Reviewed
✓ Yes

Dataset

Last updated: August 25, 2025 6:33 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.