Description
Jenkins jira-ext Plugin 0.8 and earlier stored credentials unencrypted in its global configuration file on the Jenkins master where they could be viewed by users with access to the master file system.
Remediation
References
http://www.securityfocus.com/bid/108045
https://jenkins.io/security/advisory/2019-04-17/#SECURITY-836
Related Vulnerabilities
CVE-2022-41713 Vulnerability in npm package deep-object-diff
CVE-2021-30246 Vulnerability in maven package org.webjars.bowergithub.kjur:jsrsasign
CVE-2018-13003 Vulnerability in maven package net.opentsdb:opentsdb
CVE-2022-21169 Vulnerability in npm package express-xss-sanitizer
CVE-2017-3203 Vulnerability in maven package org.springframework.flex:spring-flex-core