{"id":"CVE-2026-57302","aliases":["GHSA-j4ph-wp3c-c37w"],"title":"Jenkins FitNesse Plugin stores passwords unencrypted","summary":"Jenkins FitNesse Plugin stores passwords unencrypted","severity":"medium","cvss":4.3,"cwe":["CWE-256"],"vendor":"jenkins-ci","product":"org.jenkins-ci.plugins:fitnesse","ecosystem":"maven","affected":["org.jenkins-ci.plugins:fitnesse <= 1.36"],"published":"2026-06-24","updated":"2026-09-25","sourceUpdated":"2026-09-25T19:46:21Z","source":"GHSA","sourceUrl":"https://github.com/advisories/GHSA-j4ph-wp3c-c37w","references":[{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-57302"},{"url":"https://www.jenkins.io/security/advisory/2026-06-24/#SECURITY-3555"},{"url":"https://github.com/advisories/GHSA-j4ph-wp3c-c37w"}],"tags":["ghsa","maven"],"epss":0.00281,"epssPercentile":0.18333,"ingestedAt":"2026-09-25T20:17:49.422Z","slug":"CVE-2026-57302","body":"## Overview\n\nJenkins FitNesse Plugin 1.36 and earlier stores passwords unencrypted in job config.xml files on the Jenkins controller as part of its configuration.\n\nThese passwords can be viewed by users with Item/Extended Read permission or access to the Jenkins controller file system.\n\nAs of publication of this advisory, there is no fix.\n\n## Affected packages\n\n- `org.jenkins-ci.plugins:fitnesse <= 1.36`\n\n## Remediation\n\nRefer to the advisory for the patched release.","depth":"sunlit","depthScore":24,"depthScoreParts":{"impact":23.7,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}