Description
Jenkins Assembla Auth Plugin stores credentials unencrypted in the global config.xml configuration file on the Jenkins master where they can be viewed by users with access to the master file system.
Remediation
References
http://www.openwall.com/lists/oss-security/2019/04/12/2
http://www.securityfocus.com/bid/107790
https://jenkins.io/security/advisory/2019-04-03/#SECURITY-1093
Related Vulnerabilities
CVE-2022-1330 Vulnerability in maven package org.webjars.bower:fullpage
CVE-2019-16776 Vulnerability in maven package org.webjars:npm
CVE-2018-1000854 Vulnerability in maven package org.esigate:esigate-core
CVE-2019-9212 Vulnerability in maven package com.alipay.sofa:hessian
CVE-2020-17532 Vulnerability in maven package org.apache.servicecomb:foundation-config