GHSA-vhxq-9mpv-gj87
GitHub Security Advisory
Private key stored in plain text by Jenkins Google Compute Engine Plugin
✓ GitHub Reviewed
MODERATE
Has CVE
Advisory Details
Jenkins Google Compute Engine Plugin 4.3.8 and earlier stores private keys unencrypted in cloud agent `config.xml` files on the Jenkins controller where they can be viewed by users with Agent/Extended Read permission, or access to the Jenkins controller file system.
Affected Packages
Maven
org.jenkins-ci.plugins:google-compute-engine
Affected versions:
0
(fixed in 4.3.9)
Related CVEs
Key Information
5.0
/10
Dataset
Last updated: July 4, 2025 6:27 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.