CVE-2023-50776

MEDIUM

Jenkins PaaSLane Estimate Plugin <= 1.0.4 - Cleartext Storage of Sensitive Information in Job config.xml

Title source: llm
STIX 2.1

Description

Jenkins PaaSLane Estimate Plugin 1.0.4 and earlier stores PaaSLane authentication tokens unencrypted in job config.xml files on the Jenkins controller where they can be viewed by users with Item/Extended Read permission or access to the Jenkins controller file system.

References (2)

Core 2

Scores

CVSS v3 4.3
EPSS 0.0034
EPSS Percentile 25.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Details

CWE
CWE-312
Status published
Products (2)
com.cloudtp.jenkins/paaslane-estimate 0Maven
jenkins/paaslane_estimate < 1.0.4
Published Dec 13, 2023
Tracked Since Feb 18, 2026