Vulnerabilities > Jenkins > Github Pull Request Coverage Status > 1.9.1

DATE CVE VULNERABILITY TITLE RISK
2023-01-26 CVE-2023-24442 Cleartext Storage of Sensitive Information vulnerability in Jenkins Github Pull Request Coverage Status
Jenkins GitHub Pull Request Coverage Status Plugin 2.2.0 and earlier stores the GitHub Personal Access Token, Sonar access token and Sonar password unencrypted in its global configuration file on the Jenkins controller where they can be viewed by users with access to the Jenkins controller file system.
local
low complexity
jenkins CWE-312
5.5