Description
Jenkins ElasticBox CI Plugin stores credentials unencrypted in the global config.xml configuration file on the Jenkins master where they can be viewed by users with access to the master file system.
Remediation
References
https://jenkins.io/security/advisory/2019-10-16/#SECURITY-1434
Related Vulnerabilities
CVE-2021-41084 Vulnerability in maven package org.http4s:http4s-server_3
CVE-2019-10295 Vulnerability in maven package org.jenkins-ci.plugins:crittercism-dsym
CVE-2018-1999020 Vulnerability in maven package org.onosproject:onos-core-common
CVE-2016-6636 Vulnerability in maven package org.cloudfoundry.identity:cloudfoundry-identity-server
CVE-2022-43403 Vulnerability in maven package org.jenkins-ci.plugins:script-security