Jenkins SCTMExecutor Plugin 2.2 and earlier exposes service credentials in plain text

Jenkins SCTMExecutor Plugin 2.2 and earlier exposes service credentials in plain text

CVE-2019-16568 · MEDIUM Severity

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Jenkins SCTMExecutor Plugin 2.2 and earlier transmits previously configured service credentials in plain text as part of the global configuration, as well as individual jobs' configurations.

Learn more about our Web Application Penetration Testing UK.