Description
Jenkins Assembla Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with access to the master file system.
Remediation
References
http://www.openwall.com/lists/oss-security/2019/09/25/3
https://jenkins.io/security/advisory/2019-09-25/#SECURITY-1543
Related Vulnerabilities
CVE-2020-7766 Vulnerability in maven package org.webjars.npm:json-ptr
CVE-2022-36893 Vulnerability in maven package org.jenkins-ci.plugins:rpmsign-plugin
CVE-2022-24198 Vulnerability in maven package com.itextpdf:itext7-core
CVE-2023-26031 Vulnerability in maven package org.apache.hadoop:hadoop-yarn-project
CVE-2010-2076 Vulnerability in maven package org.apache.axis2:axis2-kernel