Description
Jenkins Azure PublisherSettings Credentials Plugin 1.2 and earlier stored credentials unencrypted in the credentials.xml file on the Jenkins master where they could be viewed by users with access to the master file system.
Remediation
References
http://www.securityfocus.com/bid/108045
https://jenkins.io/security/advisory/2019-04-17/#SECURITY-844
Related Vulnerabilities
CVE-2018-20677 Vulnerability in maven package org.webjars.bowergithub.jasny:bootstrap
CVE-2022-36895 Vulnerability in maven package com.compuware.jenkins:compuware-topaz-utilities
CVE-2018-11694 Vulnerability in maven package org.webjars.npm:node-sass
CVE-2021-23399 Vulnerability in npm package wincred
CVE-2020-2251 Vulnerability in maven package org.jenkins-ci.plugins:soapui-pro-functional-testing