Description
Jenkins Sonar Gerrit Plugin stores credentials unencrypted in job config.xml files on the Jenkins master where they can be viewed by users with Extended Read permission, or access to the master file system.
Remediation
References
http://www.openwall.com/lists/oss-security/2019/10/23/2
https://jenkins.io/security/advisory/2019-10-23/#SECURITY-1003
Related Vulnerabilities
CVE-2022-28889 Vulnerability in maven package org.apache.druid:druid
CVE-2020-2157 Vulnerability in maven package org.jenkins-ci.plugins:skytap
CVE-2019-10173 Vulnerability in maven package com.thoughtworks.xstream:xstream
CVE-2022-23510 Vulnerability in npm package @cubejs-backend/api-gateway
CVE-2021-21347 Vulnerability in maven package com.thoughtworks.xstream:xstream