Jenkins ReadyAPI Functional Testing Plugin
cpe:2.3:a:jenkins:soapui_pro_functional_testing:*:*:*:*:jenkins:*:*
- <= 1.11
A vulnerability exists in the Jenkins ReadyAPI Functional Testing Plugin in versions through 1.11, where sensitive information such as SLM License Access Keys, client secrets, and passwords are stored unencrypted in job config.xml files on the Jenkins controller. This information can be accessed by users with Item/Extended Read permission or those who have access to the Jenkins controller file system.
The vulnerability allows for unauthorized access to sensitive credentials, which could be misused for various malicious purposes, depending on the nature of the stored information.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.