Description
Jenkins Official OWASP ZAP Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with access to the master file system.
Remediation
References
http://www.openwall.com/lists/oss-security/2019/04/12/2
http://www.securityfocus.com/bid/107790
https://jenkins.io/security/advisory/2019-04-03/#SECURITY-1041
Related Vulnerabilities
CVE-2022-27340 Vulnerability in maven package net.mingsoft:ms-mcms
CVE-2022-25904 Vulnerability in npm package safe-eval
CVE-2021-41164 Vulnerability in maven package org.webjars.npm:ckeditor4
CVE-2015-5211 Vulnerability in maven package org.springframework:spring-web
CVE-2020-16041 Vulnerability in maven package org.webjars.npm:electron