CVE-2019-1003060: High severity owasp zap vulnerability
Jenkins Official OWASP ZAP Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with access to the master file system.
Other sources
Jenkins Official OWASP ZAP Plugin stores Jira credentials unencrypted in its global configuration file org.jenkinsci.plugins.zap.ZAPBuilder.xml on the Jenkins controller. These credentials can be viewed by users with access to the Jenkins controller file system.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-1003060?
CVE-2019-1003060 is considered a high severity vulnerability due to the storage of unencrypted credentials.
How do I fix CVE-2019-1003060?
To fix CVE-2019-1003060, upgrade the Jenkins Official OWASP ZAP Plugin to version 1.1.1 or later.
What are the potential risks of CVE-2019-1003060?
The risks of CVE-2019-1003060 include unauthorized access to stored credentials, leading to potential data breaches.
Which versions of the Jenkins Official OWASP ZAP Plugin are affected by CVE-2019-1003060?
CVE-2019-1003060 affects all versions of the Jenkins Official OWASP ZAP Plugin up to and including 1.1.0.
Who can exploit CVE-2019-1003060?
CVE-2019-1003060 can be exploited by any user with access to the Jenkins master file system.