Description
Jenkins SOASTA CloudTest Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with access to the master file system.
Remediation
References
https://jenkins.io/security/advisory/2019-10-16/#SECURITY-1439
Related Vulnerabilities
CVE-2019-12421 Vulnerability in maven package org.apache.nifi:nifi-web-api
CVE-2020-27219 Vulnerability in maven package org.eclipse.hawkbit:hawkbit-update-server
CVE-2022-44645 Vulnerability in maven package org.apache.linkis:linkis-metadata-query-service-jdbc
CVE-2023-40014 Vulnerability in npm package @openzeppelin/contracts-upgradeable
CVE-2015-5348 Vulnerability in maven package org.apache.camel:camel-http-common