Jenkins Nouvola DiveCloud Plugin Plaintext Storage of API Keys Vulnerability
Vulnerability
A vulnerability exists in the Jenkins Nouvola DiveCloud Plugin in versions through 1.08, where DiveCloud API Keys and Credentials Encryption Keys are stored unencrypted in job config.xml files on the Jenkins controller. This information can be accessed by users with Item/Extended Read permission or those who have access to the Jenkins controller file system.
Impact
The vulnerability allows for unauthorized access to sensitive API keys and encryption keys, which could be misused to access DiveCloud services or decrypt sensitive information.
Added: Jul 9, 2025, 4:38 PM
Updated: Jul 9, 2025, 4:38 PM
Vulnerability Rating
Custom Algorithm
spread
0.0impact
2.5exploitability
5.2remediation
0.0relevance
0.2threat
0.0urgency
2.9incentive
1.7Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
