Description
Jenkins Azure AD Plugin 0.3.3 and earlier stored the client secret unencrypted in the global config.xml configuration file on the Jenkins master where it could be viewed by users with access to the master file system.
Remediation
References
http://www.openwall.com/lists/oss-security/2019/04/30/5
http://www.securityfocus.com/bid/108159
https://jenkins.io/security/advisory/2019-04-30/#SECURITY-1390
Related Vulnerabilities
CVE-2019-10798 Vulnerability in npm package rdf-graph-array
CVE-2022-36896 Vulnerability in maven package com.compuware.jenkins:compuware-scm-downloader
CVE-2023-36542 Vulnerability in maven package org.apache.nifi:nifi-standard-processors
CVE-2023-33725 Vulnerability in maven package org.broadleafcommerce:broadleaf
CVE-2019-0225 Vulnerability in maven package org.apache.jspwiki:jspwiki-builder