Description
Jenkins Audit to Database Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with access to the master file system.
Remediation
References
http://www.openwall.com/lists/oss-security/2019/04/12/2
http://www.securityfocus.com/bid/107790
https://jenkins.io/security/advisory/2019-04-03/#SECURITY-966
Related Vulnerabilities
CVE-2021-44868 Vulnerability in maven package net.mingsoft:ms-mcms
CVE-2019-10475 Vulnerability in maven package org.jenkins-ci.plugins:build-metrics
CVE-2019-20174 Vulnerability in maven package org.webjars.npm:auth0-lock
CVE-2021-31805 Vulnerability in maven package org.apache.struts:struts2-core
CVE-2022-23710 Vulnerability in maven package org.elasticsearch:elasticsearch