Description
Jenkins NeuVector Vulnerability Scanner Plugin 1.5 and earlier stored credentials unencrypted in its global configuration file on the Jenkins master where they could be viewed by users with access to the master file system.
Remediation
References
http://www.openwall.com/lists/oss-security/2019/09/25/3
https://jenkins.io/security/advisory/2019-09-25/#SECURITY-1504
Related Vulnerabilities
CVE-2023-28678 Vulnerability in maven package org.jenkins-ci.plugins:cppcheck
CVE-2020-13943 Vulnerability in maven package org.apache.tomcat:tomcat-coyote
CVE-2022-43424 Vulnerability in maven package com.compuware.jenkins:compuware-xpediter-code-coverage
CVE-2020-9489 Vulnerability in maven package org.apache.tika:tika-parsers
CVE-2021-31805 Vulnerability in maven package org.apache.struts:struts2-core