Description
Jenkins aws-device-farm Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with access to the master file system.
Remediation
References
http://www.openwall.com/lists/oss-security/2019/04/12/2
http://www.securityfocus.com/bid/107790
https://jenkins.io/security/advisory/2019-04-03/#SECURITY-835
Related Vulnerabilities
CVE-2023-47324 Vulnerability in maven package org.silverpeas.core:silverpeas-core-web
CVE-2019-17566 Vulnerability in maven package org.apache.xmlgraphics:batik-svgrasterizer
CVE-2022-32549 Vulnerability in maven package org.apache.sling:org.apache.sling.commons.log
CVE-2020-6452 Vulnerability in maven package org.webjars.npm:electron
CVE-2023-22893 Vulnerability in npm package @strapi/plugin-users-permissions