Executive brief
Jenkins OpenId Connect Authentication Plugin showed plain text client secret in configuration form
Affected products
- Maven org.jenkins-ci.plugins:oic-auth
Junglewise Threat Intelligence
CVE-2019-1003021 · Severity: low · CVSS 3 · Published 2022-05-13
Technologies: org.jenkins-ci.plugins:oic-auth (Maven). Vendors: Maven.
Jenkins OpenId Connect Authentication Plugin showed plain text client secret in configuration form