Description
Jenkins Delphix Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with access to the master file system.
Remediation
References
http://www.openwall.com/lists/oss-security/2019/10/16/6
https://jenkins.io/security/advisory/2019-10-16/#SECURITY-1450
Related Vulnerabilities
CVE-2022-44729 Vulnerability in maven package org.apache.xmlgraphics:batik-transcoder
CVE-2020-8137 Vulnerability in npm package fastify
CVE-2023-24789 Vulnerability in maven package org.jeecgframework.boot:jeecg-boot-parent
CVE-2020-7616 Vulnerability in npm package express-mock-middleware
CVE-2021-21290 Vulnerability in maven package io.netty:netty-transport-native-unix-common-tests