Description
Jenkins CodeScan Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with access to the master file system.
Remediation
References
http://www.openwall.com/lists/oss-security/2019/09/25/3
https://jenkins.io/security/advisory/2019-09-25/#SECURITY-1551
Related Vulnerabilities
CVE-2019-9212 Vulnerability in maven package com.alipay.sofa:hessian
CVE-2020-5497 Vulnerability in maven package org.mitre:openid-connect-common
CVE-2021-23375 Vulnerability in npm package psnode
CVE-2020-13951 Vulnerability in maven package org.apache.openmeetings:openmeetings-server
CVE-2020-8127 Vulnerability in maven package org.webjars.bower:reveal.js