Description
Jenkins Crowd Integration Plugin stores credentials unencrypted in the global config.xml configuration file on the Jenkins master where they can be viewed by users with access to the master file system.
Remediation
References
http://www.openwall.com/lists/oss-security/2019/04/12/2
http://www.securityfocus.com/bid/107790
https://jenkins.io/security/advisory/2019-04-03/#SECURITY-1069
Related Vulnerabilities
CVE-2020-13947 Vulnerability in maven package org.apache.activemq:activemq-web-console
CVE-2020-7623 Vulnerability in npm package jscover
CVE-2023-43123 Vulnerability in maven package org.apache.storm:storm-client
CVE-2023-31206 Vulnerability in maven package org.apache.inlong:manager-pojo
CVE-2018-11804 Vulnerability in maven package org.apache.spark:spark-core_2.10