Description
Jenkins Sametime Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with access to the master file system.
Remediation
References
http://www.openwall.com/lists/oss-security/2019/04/12/2
http://www.securityfocus.com/bid/107790
https://jenkins.io/security/advisory/2019-04-03/#SECURITY-1090
Related Vulnerabilities
CVE-2020-2252 Vulnerability in maven package org.jenkins-ci.plugins:mailer
CVE-2022-42890 Vulnerability in maven package org.apache.xmlgraphics:batik-script
CVE-2020-6537 Vulnerability in npm package electron
CVE-2019-9142 Vulnerability in maven package org.b3log:symphony
CVE-2018-1000614 Vulnerability in maven package org.onosproject:onos-netconf-provider-alarm