Jenkins Official OWASP ZAP Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with access to the master file system.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HJenkins Official Owasp Zap
APPJenkinsall versions
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
Tags
CI/CD
CWE
Related vulnerabilities
CVE-2026-57301HIGH8.8same product
Jenkins OWASP ZAP Plugin 1.0.7 and earlier performs build operations on the Jenkins controller rather than the...
CVE-2024-23897CRITICAL9.8⚠ KEVPL ✓same vendor
Jenkins CLI – odczyt dowolnych plików przez path traversal bez uwierzytelnienia
CVE-2019-1003030CRITICAL9.9⚠ KEVPL ✓same vendor
Jenkins Pipeline Groovy Plugin — bypass sandbox i wykonanie kodu (RCE)
CVE-2019-1003029CRITICAL9.9⚠ KEVPL ✓same vendor
Jenkins Script Security Plugin — sandbox bypass umożliwiający RCE
CVE-2018-1000861CRITICAL9.8⚠ KEVPL ✓same vendor
RCE w Jenkins — nieuprawnione wywołanie metod przez Stapler framework