Description
Jenkins VS Team Services Continuous Deployment Plugin stores credentials unencrypted in job config.xml files on the Jenkins master where they can be viewed by users with Extended Read permission, or access to the master file system.
Remediation
References
http://www.openwall.com/lists/oss-security/2019/04/12/2
http://www.securityfocus.com/bid/107790
https://jenkins.io/security/advisory/2019-04-03/#SECURITY-962
Related Vulnerabilities
CVE-2022-25858 Vulnerability in maven package org.webjars.npm:terser
CVE-2022-25168 Vulnerability in maven package org.apache.hadoop:hadoop-common
CVE-2020-28481 Vulnerability in npm package socket.io
CVE-2017-7660 Vulnerability in maven package org.apache.solr:solr-core
CVE-2022-45802 Vulnerability in maven package org.apache.streampark:streampark-common_2.12