Description
Jenkins CodeScan Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with access to the master file system.
Remediation
References
http://www.openwall.com/lists/oss-security/2019/09/25/3
https://jenkins.io/security/advisory/2019-09-25/#SECURITY-1551
Related Vulnerabilities
CVE-2021-46877 Vulnerability in maven package com.fasterxml.jackson.core:jackson-databind
CVE-2021-21234 Vulnerability in maven package eu.hinsch:spring-boot-actuator-logview
CVE-2022-3509 Vulnerability in maven package com.google.protobuf:protobuf-javalite
CVE-2022-31189 Vulnerability in maven package org.dspace:dspace-jspui