Description
Jenkins Bugzilla Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with access to the master file system.
Remediation
References
http://www.openwall.com/lists/oss-security/2019/04/12/2
http://www.securityfocus.com/bid/107790
https://jenkins.io/security/advisory/2019-04-03/#SECURITY-841
Related Vulnerabilities
CVE-2023-0842 Vulnerability in maven package org.webjars.npm:xml2js
CVE-2022-31129 Vulnerability in maven package org.webjars:momentjs
CVE-2022-33987 Vulnerability in npm package got
CVE-2022-34115 Vulnerability in maven package io.dataease:dataease-plugin-common
CVE-2020-2181 Vulnerability in maven package org.jenkins-ci.plugins:credentials-binding