Description
Jenkins Aqua MicroScanner Plugin 1.0.5 and earlier stored credentials unencrypted in its global configuration file on the Jenkins master where they could be viewed by users with access to the master file system.
Remediation
References
http://www.openwall.com/lists/oss-security/2019/04/30/5
http://www.securityfocus.com/bid/108159
https://jenkins.io/security/advisory/2019-04-30/#SECURITY-1380
Related Vulnerabilities
CVE-2022-2047 Vulnerability in maven package org.eclipse.jetty:jetty-http
CVE-2021-41561 Vulnerability in maven package org.apache.parquet:parquet
CVE-2023-31453 Vulnerability in maven package org.apache.inlong:manager-web
CVE-2021-3666 Vulnerability in npm package body-parser-xml
CVE-2021-29459 Vulnerability in maven package org.xwiki.platform:xwiki-platform-web