Jenkins SAML Plugin
cpe:2.3:a:jenkins:saml:*:*:*:*:jenkins:*:*
- <= 4.583.vc68232f7018a_
A vulnerability exists in the Jenkins ByteGuard Build Actions Plugin in version 1.0 and earlier, where API tokens are stored unencrypted in job configuration files on the Jenkins controller. The tokens can be accessed by users with Item/Extended Read permission or those who have access to the Jenkins controller file system. Furthermore, the job configuration form fails to mask these tokens, heightening the risk of unauthorized observation and capture.
The vulnerability allows for unauthorized access to API tokens, which could be intercepted and misused.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.