Loading HuntDB...

GHSA-p68c-xg89-2g5r

GitHub Security Advisory

Credentials transmitted in plain text by Backlog Plugin

✓ GitHub Reviewed LOW Has CVE

Advisory Details

Backlog Plugin stores credentials in job `config.xml` files as part of its configuration.

While the credentials are stored encrypted on disk, they are transmitted in plain text as part of the configuration form by Backlog Plugin 2.4 and earlier. These credentials could be viewed by users with Extended Read permission.

Affected Packages

Maven org.jenkins-ci.plugins:backlog
Affected versions: 0 (fixed in 2.5)

Related CVEs

Key Information

GHSA ID
GHSA-p68c-xg89-2g5r
Published
May 24, 2022 5:10 PM
Last Modified
January 14, 2023 5:25 AM
CVSS Score
2.5 /10
Primary Ecosystem
Maven
Primary Package
org.jenkins-ci.plugins:backlog
GitHub Reviewed
✓ Yes

Dataset

Last updated: August 25, 2025 6:33 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.