Description
Jenkins Serena SRA Deploy Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with access to the master file system.
Remediation
References
http://www.openwall.com/lists/oss-security/2019/04/12/2
http://www.securityfocus.com/bid/107790
https://jenkins.io/security/advisory/2019-04-03/#SECURITY-1066
Related Vulnerabilities
CVE-2020-15170 Vulnerability in maven package com.ctrip.framework.apollo:apollo-adminservice
CVE-2019-10775 Vulnerability in maven package org.webjars.npm:ecstatic
CVE-2021-20086 Vulnerability in npm package jquery-bbq
CVE-2022-36916 Vulnerability in maven package org.jenkins-ci.plugins:google-cloud-backup
CVE-2019-10282 Vulnerability in maven package hudson.plugins.klaros:klaros-testmanagement