Description
Jenkins NeuVector Vulnerability Scanner Plugin 1.5 and earlier stored credentials unencrypted in its global configuration file on the Jenkins master where they could be viewed by users with access to the master file system.
Remediation
References
http://www.openwall.com/lists/oss-security/2019/09/25/3
https://jenkins.io/security/advisory/2019-09-25/#SECURITY-1504
Related Vulnerabilities
CVE-2022-29265 Vulnerability in maven package org.apache.nifi:nifi
CVE-2022-42889 Vulnerability in maven package org.apache.commons:commons-text
CVE-2021-32013 Vulnerability in npm package xlsx
CVE-2023-32314 Vulnerability in maven package org.webjars.npm:vm2
CVE-2019-1003071 Vulnerability in maven package hudson.plugins.octopusdeploy:octopusdeploy