Description
Jenkins Crowd Integration Plugin stores credentials unencrypted in the global config.xml configuration file on the Jenkins master where they can be viewed by users with access to the master file system.
Remediation
References
http://www.openwall.com/lists/oss-security/2019/04/12/2
http://www.securityfocus.com/bid/107790
https://jenkins.io/security/advisory/2019-04-03/#SECURITY-1069
Related Vulnerabilities
CVE-2022-31103 Vulnerability in npm package lettersanitizer
CVE-2023-51075 Vulnerability in maven package cn.hutool:hutool-core
CVE-2020-8237 Vulnerability in maven package org.webjars.bower:json-bigint
CVE-2019-18798 Vulnerability in npm package node-sass
CVE-2022-41401 Vulnerability in maven package org.openrefine:main