Description
Jenkins SCTMExecutor Plugin 2.2 and earlier transmits previously configured service credentials in plain text as part of the global configuration, as well as individual jobs' configurations.
Remediation
References
http://www.openwall.com/lists/oss-security/2019/12/17/1
https://jenkins.io/security/advisory/2019-12-17/#SECURITY-1521
Related Vulnerabilities
CVE-2022-48285 Vulnerability in maven package org.webjars:jszip
CVE-2021-37695 Vulnerability in maven package org.webjars.npm:ckeditor4
CVE-2019-18213 Vulnerability in maven package org.lsp4xml:org.eclipse.lsp4xml.extensions.emmet
CVE-2021-25915 Vulnerability in npm package changeset
CVE-2019-10381 Vulnerability in maven package org.jenkins-ci.plugins:codefresh