GHSA-v3r8-6vfj-pppf
GitHub Security Advisory
Plaintext Storage of a Password in Jenkins Build Notifications Plugin
✓ GitHub Reviewed
LOW
Has CVE
Advisory Details
Build Notifications Plugin 1.5.0 and earlier stores multiple tokens unencrypted in its global configuration files on the Jenkins controller as part of its configuration:- Pushover Application Token in `tools.devnull.jenkins.plugins.buildnotifications.PushoverNotifier.xml`\n- Slack Bot Token in `tools.devnull.jenkins.plugins.buildnotifications.SlackNotifier.xml`\n- Telegram Bot Token in `tools.devnull.jenkins.plugins.buildnotifications.TelegramNotifier.xml`
Affected Packages
Maven
tools.devnull:build-notifications
Affected versions:
0
(last affected: 1.5.0)
Related CVEs
Key Information
2.5
/10
Dataset
Last updated: August 25, 2025 6:33 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.