LOW 3.3 Maven

Jenkins Amazon SNS Build Notifier Plugin stores credentials in plain text

GHSA-84p4-7mxc-7phj · CVE-2019-1003063

Published · Modified

AI SAST

Find this class of vulnerability in your own code

Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.

Description

Jenkins Amazon SNS Build Notifier Plugin stores credentials unencrypted in its global configuration file org.jenkinsci.plugins.snsnotify.AmazonSNSNotifier.xml on the Jenkins controller. These credentials can be viewed by users with access to the Jenkins controller file system.

Ready to move

Start Securing

Free, no credit card | First findings in minutes