Description
Jenkins Dynamic Extended Choice Parameter Plugin 1.0.1 and earlier stores a password unencrypted in job config.xml files on the Jenkins master where it can be viewed by users with Extended Read permission, or access to the master file system.
Remediation
References
http://www.openwall.com/lists/oss-security/2020/02/12/3
https://jenkins.io/security/advisory/2020-02-12/#SECURITY-1560
Related Vulnerabilities
CVE-2019-10286 Vulnerability in maven package com.openmake:deployhub
CVE-2022-35949 Vulnerability in maven package org.webjars.npm:undici
CVE-2015-8855 Vulnerability in maven package org.webjars.bower:semver
CVE-2023-31062 Vulnerability in maven package org.apache.inlong:manager-service
CVE-2020-2296 Vulnerability in maven package org.jenkins-ci.plugins:shared-objects