Description
Jenkins Gogs Plugin stored credentials unencrypted in job config.xml files on the Jenkins master where they can be viewed by users with Extended Read permission, or access to the master file system.
Remediation
References
http://www.openwall.com/lists/oss-security/2019/07/11/4
http://www.securityfocus.com/bid/109156
https://jenkins.io/security/advisory/2019-07-11/#SECURITY-1438
https://www.zerodayinitiative.com/advisories/ZDI-19-837/
Related Vulnerabilities
CVE-2020-10727 Vulnerability in maven package org.apache.activemq:artemis-server
CVE-2023-46122 Vulnerability in maven package org.scala-sbt:io_2.12
CVE-2020-5245 Vulnerability in maven package io.dropwizard:dropwizard-validation
CVE-2019-1003041 Vulnerability in maven package org.jenkins-ci.plugins:groovy
CVE-2019-16728 Vulnerability in maven package org.webjars.bowergithub.cure53:dompurify