Description
Jenkins Crowd Integration Plugin stores credentials unencrypted in the global config.xml configuration file on the Jenkins master where they can be viewed by users with access to the master file system.
Remediation
References
http://www.openwall.com/lists/oss-security/2019/04/12/2
http://www.securityfocus.com/bid/107790
https://jenkins.io/security/advisory/2019-04-03/#SECURITY-1069
Related Vulnerabilities
CVE-2020-2239 Vulnerability in maven package org.jenkins-ci.plugins:parameterized-remote-trigger
CVE-2023-28754 Vulnerability in maven package org.apache.shardingsphere:shardingsphere
CVE-2022-41881 Vulnerability in maven package io.netty:netty-codec-haproxy
CVE-2023-31454 Vulnerability in maven package org.apache.inlong:manager-service
CVE-2019-0219 Vulnerability in npm package cordova-plugin-inappbrowser