CVE-2026-57302
Received
Received - Intake
Jenkins FitNesse Plugin Password Exposure Vulnerability
Publication date: 2026-06-24
Last updated on: 2026-06-24
Assigner: Jenkins Project
Description
Description
Jenkins FitNesse Plugin 1.36 and earlier stores passwords unencrypted in job config.xml files on the Jenkins controller, where they can be viewed by users with Extended Read permission or access to the Jenkins controller file system.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| jenkinsci | fitnesse_plugin | to 1.37 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-256 | The product stores a password in plaintext within resources such as memory or files. |