CVE-2017-1000245

CRITICAL9.8EPSS 0.06%

Jenkins SSH Plugin user passwords for encrypted SSH keys stored in plaintext

Published: 5/13/2022Modified: 2/18/2024
Also known as:GHSA-5gmf-8gh2-hhfp

Description

The SSH Plugin stores credentials which allow jobs to access remote servers via the SSH protocol. User passwords and passphrases for encrypted SSH keys are stored in plaintext in a configuration file.

Affected packages (2)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1CRITICAL9.8CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

References (2)