{"id":"GHSA-jmp9-f42q-4g85","summary":"Passwords stored in plain text by Harvest SCM Plugin","details":"Harvest SCM Plugin 0.5.1 and earlier stores SCM passwords unencrypted in its global configuration file `hudson.plugins.harvest.HarvestSCM.xml and in job config.xml` files on the Jenkins controller. These credentials can be viewed by users with Extended Read permission (job config.xml only) or access to the Jenkins controller file system (both).","aliases":["CVE-2020-2130"],"modified":"2024-02-16T08:05:41.715148Z","published":"2022-05-24T17:08:48Z","database_specific":{"cwe_ids":["CWE-256","CWE-522"],"github_reviewed_at":"2023-01-05T21:44:12Z","github_reviewed":true,"nvd_published_at":"2020-02-12T15:15:00Z","severity":"MODERATE"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2020-2130"},{"type":"PACKAGE","url":"https://github.com/jenkinsci/harvest-plugin"},{"type":"WEB","url":"https://jenkins.io/security/advisory/2020-02-12/#SECURITY-1553"},{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2020/02/12/3"}],"affected":[{"package":{"name":"org.jenkins-ci.plugins:harvest","ecosystem":"Maven","purl":"pkg:maven/org.jenkins-ci.plugins/harvest"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"0.5.1"}]}],"versions":["0.4.2","0.5","0.5.1"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-jmp9-f42q-4g85/GHSA-jmp9-f42q-4g85.json"}}],"schema_version":"1.7.3","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"}]}