Description
A vulnerability in Jenkins PRQA Plugin 3.1.0 and earlier allows attackers with local file system access to the Jenkins home directory to obtain the unencrypted password from the plugin configuration.
Remediation
References
http://www.openwall.com/lists/oss-security/2019/03/28/2
http://www.securityfocus.com/bid/107628
https://jenkins.io/security/advisory/2019-03-25/#SECURITY-1089
Related Vulnerabilities
CVE-2023-28708 Vulnerability in maven package org.apache.tomcat.embed:tomcat-embed-core
CVE-2020-17527 Vulnerability in maven package org.apache.tomcat.embed:tomcat-embed-core
CVE-2020-7762 Vulnerability in npm package jsreport-chrome-pdf
CVE-2021-21122 Vulnerability in maven package org.webjars.npm:electron