Description
Jenkins Azure PublisherSettings Credentials Plugin 1.2 and earlier stored credentials unencrypted in the credentials.xml file on the Jenkins master where they could be viewed by users with access to the master file system.
Remediation
References
http://www.securityfocus.com/bid/108045
https://jenkins.io/security/advisory/2019-04-17/#SECURITY-844
Related Vulnerabilities
CVE-2020-6451 Vulnerability in npm package electron
CVE-2018-19586 Vulnerability in maven package org.silverpeas.core:silverpeas-core-web
CVE-2021-21290 Vulnerability in maven package io.netty:netty-transport-native-epoll
CVE-2022-38900 Vulnerability in maven package org.webjars.npm:decode-uri-component