Description
Jenkins Azure PublisherSettings Credentials Plugin 1.2 and earlier stored credentials unencrypted in the credentials.xml file on the Jenkins master where they could be viewed by users with access to the master file system.
Remediation
References
http://www.securityfocus.com/bid/108045
https://jenkins.io/security/advisory/2019-04-17/#SECURITY-844
Related Vulnerabilities
CVE-2020-11112 Vulnerability in maven package com.fasterxml.jackson.core:jackson-databind
CVE-2016-6346 Vulnerability in maven package org.jboss.resteasy:resteasy-jaxrs
CVE-2021-39168 Vulnerability in npm package @openzeppelin/contracts-upgradeable
CVE-2022-21830 Vulnerability in npm package @rocket.chat/livechat