LOW3.3
GHSA-84p4-7mxc-7phj
Jenkins Amazon SNS Build Notifier Plugin stores credentials in plain text
Quick fix
GHSA-84p4-7mxc-7phj — org.jenkins-ci.plugins:snsnotify: upgrade to the fixed version with the command below.
# pom.xml: bump <version>2.37</version> for org.jenkins-ci.plugins:snsnotifyDetails
Jenkins Amazon SNS Build Notifier Plugin stores credentials unencrypted in its global configuration file `org.jenkinsci.plugins.snsnotify.AmazonSNSNotifier.xml` on the Jenkins controller. These credentials can be viewed by users with access to the Jenkins controller file system.
Are you affected?
Enter the version of the package you're using.
Affected packages
Maven/org.jenkins-ci.plugins:snsnotify
Introduced in:
0Fixed in: 2.37Fix
# pom.xml: bump <version>2.37</version> for org.jenkins-ci.plugins:snsnotifyReferences
- https://nvd.nist.gov/vuln/detail/CVE-2019-1003063[ADVISORY]
- https://github.com/jenkinsci/snsnotify-plugin/commit/874db1f2882aebb452c6d9dc0ad59efa6fd336db[WEB]
- https://github.com/jenkinsci/snsnotify-plugin[PACKAGE]
- https://jenkins.io/security/advisory/2019-04-03/#SECURITY-832[WEB]
- http://www.openwall.com/lists/oss-security/2019/04/12/2[WEB]