Description
Jenkins Maven Release Plugin 0.14.0 and earlier stored credentials unencrypted on the Jenkins master where they could be viewed by users with access to the master file system.
Remediation
References
http://www.openwall.com/lists/oss-security/2019/07/31/1
https://jenkins.io/security/advisory/2019-07-31/#SECURITY-1435
https://www.zerodayinitiative.com/advisories/ZDI-19-835/
Related Vulnerabilities
CVE-2018-11765 Vulnerability in maven package org.apache.hadoop:hadoop-common
CVE-2020-2181 Vulnerability in maven package org.jenkins-ci.plugins:credentials-binding
CVE-2011-4367 Vulnerability in maven package org.apache.myfaces.core:myfaces-impl
CVE-2023-51079 Vulnerability in maven package org.mvel:mvel2
CVE-2020-11971 Vulnerability in maven package org.apache.camel:camel-management