Description
Jenkins ECX Copy Data Management Plugin 1.9 and earlier stores a password unencrypted in job config.xml files on the Jenkins master where it can be viewed by users with Extended Read permission, or access to the master file system.
Remediation
References
http://www.openwall.com/lists/oss-security/2020/02/12/3
https://jenkins.io/security/advisory/2020-02-12/#SECURITY-1549
Related Vulnerabilities
CVE-2020-36650 Vulnerability in npm package gry
CVE-2019-13234 Vulnerability in maven package org.opencms:opencms-core
CVE-2022-24822 Vulnerability in npm package @podium/layout
CVE-2022-35961 Vulnerability in npm package @openzeppelin/contracts-upgradeable
CVE-2019-12423 Vulnerability in maven package org.apache.cxf:cxf-rt-rs-security-jose