Description
Jenkins veracode-scanner Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with access to the master file system.
Remediation
References
http://www.openwall.com/lists/oss-security/2019/04/12/2
http://www.securityfocus.com/bid/107790
https://jenkins.io/security/advisory/2019-04-03/#SECURITY-952
Related Vulnerabilities
CVE-2020-5207 Vulnerability in maven package io.ktor:ktor-client-cio
CVE-2016-6793 Vulnerability in maven package org.apache.wicket:wicket-util
CVE-2022-43429 Vulnerability in maven package com.compuware.jenkins:compuware-topaz-for-total-test
CVE-2021-27405 Vulnerability in npm package @progfay/scrapbox-parser
CVE-2021-29425 Vulnerability in maven package commons-io:commons-io