CVE-2026-57302Medium· 4.3▾ SunlitJenkins FitNesse Plugin stores passwords unencrypted
▾ Sunlit zone — Low / medium · no exploitation signal
impact 23.7 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via GHSA
Last analysed / modified upstream
0.3%
Jenkins FitNesse Plugin 1.36 and earlier stores passwords unencrypted in job config.xml files on the Jenkins controller as part of its configuration.
These passwords can be viewed by users with Item/Extended Read permission or access to the Jenkins controller file system.
As of publication of this advisory, there is no fix.
org.jenkins-ci.plugins:fitnesse <= 1.36Refer to the advisory for the patched release.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-57301High· 8.8Jenkins OWASP ZAP Plugin: Builds executed on the Jenkins controller can lead to RCE
CVE-2026-57303High· 7.1Jenkins Assembla Plugin has an XXE vulnerability
CVE-2026-57305Medium· 5.4Jenkins Assembla Plugin has a cross-site request forgery (CSRF) vulnerability
CVE-2026-57304Medium· 5.4Jenkins Assembla Plugin has a missing permission check
CVE-2026-57296High· 8.8Jenkins External Workspace Manager Plugin has a path traversal vulnerability
CVE-2026-57288Low· 3.7Jenkins Active Directory Plugin has an LDAP injection vulnerability