Description
Jenkins Maven Release Plugin 0.14.0 and earlier stored credentials unencrypted on the Jenkins master where they could be viewed by users with access to the master file system.
Remediation
References
http://www.openwall.com/lists/oss-security/2019/07/31/1
https://jenkins.io/security/advisory/2019-07-31/#SECURITY-1435
https://www.zerodayinitiative.com/advisories/ZDI-19-835/
Related Vulnerabilities
CVE-2019-17352 Vulnerability in maven package com.jfinal:jfinal
CVE-2019-10424 Vulnerability in maven package com.technicolor:eloyente
CVE-2021-29445 Vulnerability in npm package jose-node-esm-runtime
CVE-2022-29230 Vulnerability in npm package @shopify/hydrogen
CVE-2019-20343 Vulnerability in maven package org.codehaus.mojo:exec-maven-plugin