Improper Synchronization in Jenkins Convertigo Mobile Platform Plugin
Low severity
GitHub Reviewed
Published
Feb 16, 2022
to the GitHub Advisory Database
•
Updated Feb 3, 2023
Package
Affected versions
<= 1.1
Patched versions
None
Description
Published by the National Vulnerability Database
Feb 15, 2022
Published to the GitHub Advisory Database
Feb 16, 2022
Reviewed
Feb 24, 2022
Last updated
Feb 3, 2023
Jenkins Convertigo Mobile Platform Plugin 1.1 and earlier uses static fields to store job configuration information, allowing attackers with Item/Configure permission to capture passwords of the jobs that will be configured.
References