Description
Jenkins Azure Event Grid Build Notifier Plugin stores credentials unencrypted in job config.xml files on the Jenkins master where they can be viewed by users with Extended Read permission, or access to the master file system.
Remediation
References
http://www.openwall.com/lists/oss-security/2019/09/25/3
https://jenkins.io/security/advisory/2019-09-25/#SECURITY-1544
Related Vulnerabilities
CVE-2023-46604 Vulnerability in maven package org.apache.activemq:activemq-openwire-legacy
CVE-2022-43411 Vulnerability in maven package org.jenkins-ci.plugins:gitlab-plugin
CVE-2019-12418 Vulnerability in maven package org.apache.tomcat:tomcat-catalina
CVE-2021-21293 Vulnerability in maven package org.http4s:blaze-core_2.12
CVE-2020-1938 Vulnerability in maven package org.apache.tomcat:tomcat-util