Description
An exposure of sensitive information vulnerability exists in Jenkins Perforce Plugin version 1.3.36 and older in PerforcePasswordEncryptor.java that allows attackers with local file system access to obtain encrypted Perforce passwords and decrypt them.
Remediation
References
https://jenkins.io/security/advisory/2018-03-26/#SECURITY-373
Related Vulnerabilities
CVE-2023-28672 Vulnerability in maven package org.jenkinsci.plugins:octoperf
CVE-2023-40037 Vulnerability in maven package org.apache.nifi:nifi-dbcp-base
CVE-2018-17244 Vulnerability in maven package org.elasticsearch:elasticsearch
CVE-2022-38398 Vulnerability in maven package org.apache.xmlgraphics:batik-bridge
CVE-2019-10325 Vulnerability in maven package io.jenkins.plugins:warnings-ng