Description
Jenkins Aqua Security Scanner Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with access to the master file system.
Remediation
References
http://www.openwall.com/lists/oss-security/2019/04/12/2
http://www.securityfocus.com/bid/107790
https://jenkins.io/security/advisory/2019-04-03/#SECURITY-949
Related Vulnerabilities
CVE-2022-39259 Vulnerability in maven package io.github.skylot:jadx-plugins-api
CVE-2021-21353 Vulnerability in npm package pug
CVE-2021-36686 Vulnerability in npm package yapi-vendor
CVE-2020-15138 Vulnerability in npm package prismjs
CVE-2021-39236 Vulnerability in maven package org.apache.ozone:ozone-main