Jenkins
cpe:2.3:a:jenkins:jenkins:*:*:*:*:*:*:*
- <= 2.503
A vulnerability exists in the Jenkins monitor-remote-job Plugin version 1.0, which stores passwords in plaintext within job config.xml files on the Jenkins controller. This unencrypted storage allows users with Extended Read permission or access to the Jenkins controller file system to view these passwords.
The vulnerability allows unauthorized users to access sensitive passwords, potentially leading to unauthorized actions or access within Jenkins or connected systems.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.