Jenkins ReadyAPI Functional Testing Plugin Plain Text Credential Storage Vulnerability

Vulnerability

A vulnerability exists in the Jenkins ReadyAPI Functional Testing Plugin in versions through 1.11, where sensitive information such as SLM License Access Keys, client secrets, and passwords are stored unencrypted in job config.xml files on the Jenkins controller. This information can be accessed by users with Item/Extended Read permission or those who have access to the Jenkins controller file system.

Impact

The vulnerability allows for unauthorized access to sensitive credentials, which could be misused for various malicious purposes, depending on the nature of the stored information.

Added: Jul 9, 2025, 5:09 PM
Updated: Jul 9, 2025, 5:09 PM

Vulnerability Rating

Custom Algorithm
spread
0.8
impact
2.5
exploitability
5.2
remediation
0.0
relevance
0.2
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.