Description
Jenkins CodeScan Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with access to the master file system.
Remediation
References
http://www.openwall.com/lists/oss-security/2019/09/25/3
https://jenkins.io/security/advisory/2019-09-25/#SECURITY-1551
Related Vulnerabilities
CVE-2022-31194 Vulnerability in maven package org.dspace:dspace-jspui
CVE-2023-2798 Vulnerability in maven package org.htmlunit:htmlunit
CVE-2020-26296 Vulnerability in maven package org.webjars.npm:vega
CVE-2020-7708 Vulnerability in npm package @irrelon/path
CVE-2023-29246 Vulnerability in maven package org.apache.openmeetings:openmeetings-web