Description
Jenkins Call Remote Job Plugin stores credentials unencrypted in job config.xml files on the Jenkins master where they can be viewed by users with Extended Read permission, or access to the master file system.
Remediation
References
http://www.openwall.com/lists/oss-security/2019/09/25/3
https://jenkins.io/security/advisory/2019-09-25/#SECURITY-1548
Related Vulnerabilities
CVE-2021-4264 Vulnerability in maven package org.webjars:dustjs-linkedin
CVE-2021-23555 Vulnerability in npm package vm2
CVE-2023-25753 Vulnerability in maven package org.apache.shenyu:shenyu-common
CVE-2020-7009 Vulnerability in maven package org.elasticsearch:elasticsearch
CVE-2022-31018 Vulnerability in maven package com.typesafe.play:play_2.13