Unprotected Storage of Credentials
Affecting org.jenkins-ci.plugins:couchdb-statistics artifact, versions [,0.4)Report new vulnerabilities
org.jenkins-ci.plugins:couchdb-statistics is a global build stats plugin that can push results to couchdb/cloudant
Affected versions of this package are vulnerable to Unprotected Storage of Credentials. It stores its server password unencrypted in its global configuration file This password can be viewed by users with access to the Jenkins controller file system.couchdb-statistics Plugin 0.4 stores its server password encrypted once its configuration is saved again.
org.jenkins-ci.plugins:couchdb-statistics to version 0.4 or higher.