Description
Jenkins Data Theorem: CI/CD Plugin 1.3 and earlier stored credentials unencrypted in job config.xml files on the Jenkins master where they could be viewed by users with Extended Read permission, or access to the master file system.
Remediation
References
http://www.openwall.com/lists/oss-security/2019/09/25/3
https://jenkins.io/security/advisory/2019-09-25/#SECURITY-1557
Related Vulnerabilities
CVE-2020-2193 Vulnerability in maven package io.jenkins.plugins:echarts-api
CVE-2022-24999 Vulnerability in npm package qs
CVE-2019-10381 Vulnerability in maven package org.jenkins-ci.plugins:codefresh
CVE-2023-37962 Vulnerability in maven package io.jenkins.plugins:benchmark-evaluator
CVE-2019-1003041 Vulnerability in maven package org.jenkins-ci.plugins:groovy