Description
Jenkins Azure PublisherSettings Credentials Plugin 1.2 and earlier stored credentials unencrypted in the credentials.xml file on the Jenkins master where they could be viewed by users with access to the master file system.
Remediation
References
http://www.securityfocus.com/bid/108045
https://jenkins.io/security/advisory/2019-04-17/#SECURITY-844
Related Vulnerabilities
CVE-2018-0114 Vulnerability in npm package node-jose
CVE-2020-28455 Vulnerability in npm package markdown-it-toc
CVE-2020-25689 Vulnerability in maven package org.wildfly.core:wildfly-protocol
CVE-2021-23364 Vulnerability in npm package browserslist
CVE-2017-5636 Vulnerability in maven package org.apache.nifi:nifi-web-security