Description
Jenkins Weibo Plugin 1.0.1 and earlier stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with access to the master file system.
Remediation
References
http://www.openwall.com/lists/oss-security/2019/12/17/1
http://www.openwall.com/lists/oss-security/2019/12/17/1
https://jenkins.io/security/advisory/2019-12-17/#SECURITY-1597
Related Vulnerabilities
CVE-2020-7676 Vulnerability in maven package org.webjars.bower:angular
CVE-2023-5572 Vulnerability in npm package @vrite/sdk
CVE-2022-25349 Vulnerability in npm package materialize-css
CVE-2020-7792 Vulnerability in maven package org.webjars.npm:mout
CVE-2018-1000632 Vulnerability in maven package org.jenkins-ci.dom4j:dom4j