CVE-2013-6372

Jenkins Subversion Plugin < 1.54 - Credential Disclosure via Base64-Encoded Storage

Title source: llm
STIX 2.1

Description

The Subversion plugin before 1.54 for Jenkins stores credentials using base64 encoding, which allows local users to obtain passwords and SSH private keys by reading a subversion.credentials file.

Scores

EPSS 0.0006
EPSS Percentile 19.0%

Details

CWE
CWE-255
Status published
Products (50)
jenkins-ci/subversion-plugin 1.0
jenkins-ci/subversion-plugin 1.1
jenkins-ci/subversion-plugin 1.2
jenkins-ci/subversion-plugin 1.3
jenkins-ci/subversion-plugin 1.4
jenkins-ci/subversion-plugin 1.5
jenkins-ci/subversion-plugin 1.6
jenkins-ci/subversion-plugin 1.7
jenkins-ci/subversion-plugin 1.8
jenkins-ci/subversion-plugin 1.9
... and 40 more
Published May 08, 2014
Tracked Since Feb 18, 2026