A vulnerability in Jenkins PRQA Plugin 3.1.0 and earlier allows attackers with local file system access to the Jenkins home directory to obtain the unencrypted password from the plugin configuration.
                
            References
                    | Link | Resource | 
|---|---|
| https://jenkins.io/security/advisory/2019-03-25/#SECURITY-1089 | Vendor Advisory | 
| http://www.openwall.com/lists/oss-security/2019/03/28/2 | Mailing List Third Party Advisory | 
| http://www.securityfocus.com/bid/107628 | Third Party Advisory VDB Entry | 
Configurations
                    Information
                Published : 2019-03-28 11:29
Updated : 2020-09-29 11:23
NVD link : CVE-2019-1003048
Mitre link : CVE-2019-1003048
JSON object : View
CWE
                
                    
                        
                        CWE-311
                        
            Missing Encryption of Sensitive Data
Products Affected
                jenkins
- prqa


