Description
Jenkins Sametime Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with access to the master file system.
Remediation
References
http://www.openwall.com/lists/oss-security/2019/04/12/2
http://www.securityfocus.com/bid/107790
https://jenkins.io/security/advisory/2019-04-03/#SECURITY-1090
Related Vulnerabilities
CVE-2020-10969 Vulnerability in maven package com.fasterxml.jackson.core:jackson-databind
CVE-2023-36478 Vulnerability in maven package org.eclipse.jetty.http2:http2-hpack
CVE-2022-35961 Vulnerability in maven package org.webjars.npm:openzeppelin__contracts
CVE-2019-15482 Vulnerability in npm package selectize-plugin-a11y
CVE-2020-2132 Vulnerability in maven package com.parasoft:environment-manager