Description
Jenkins Azure Event Grid Build Notifier Plugin stores credentials unencrypted in job config.xml files on the Jenkins master where they can be viewed by users with Extended Read permission, or access to the master file system.
Remediation
References
http://www.openwall.com/lists/oss-security/2019/09/25/3
https://jenkins.io/security/advisory/2019-09-25/#SECURITY-1544
Related Vulnerabilities
CVE-2022-41915 Vulnerability in maven package io.netty:netty-codec
CVE-2020-15156 Vulnerability in npm package nodebb-plugin-blog-comments
CVE-2022-43416 Vulnerability in maven package org.jenkins-ci.plugins:katalon
CVE-2021-32803 Vulnerability in npm package tar
CVE-2019-3772 Vulnerability in maven package org.springframework.integration:spring-integration-ws