Description
Jenkins Perfecto Mobile Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with access to the master file system.
Remediation
References
http://www.openwall.com/lists/oss-security/2019/04/12/2
http://www.securityfocus.com/bid/107790
https://jenkins.io/security/advisory/2019-04-03/#SECURITY-1061
Related Vulnerabilities
CVE-2020-2182 Vulnerability in maven package org.jenkins-ci.plugins:credentials-binding
CVE-2020-7598 Vulnerability in maven package org.webjars.npm:minimist
CVE-2023-28709 Vulnerability in maven package org.apache.tomcat:tomcat-catalina
CVE-2017-1000421 Vulnerability in maven package org.webjars:gifsicle
CVE-2022-0084 Vulnerability in maven package org.jboss.xnio:xnio-api