Description
Jenkins Parasoft Environment Manager Plugin 2.14 and earlier stores a password unencrypted in job config.xml files on the Jenkins master where it can be viewed by users with Extended Read permission, or access to the master file system.
Remediation
References
http://www.openwall.com/lists/oss-security/2020/02/12/3
https://jenkins.io/security/advisory/2020-02-12/#SECURITY-1562
Related Vulnerabilities
CVE-2021-21641 Vulnerability in maven package org.jenkins-ci.plugins:promoted-builds
CVE-2019-19919 Vulnerability in maven package org.webjars:handlebars
CVE-2020-7598 Vulnerability in maven package org.webjars.npm:minimist
CVE-2020-7660 Vulnerability in maven package org.webjars.npm:serialize-javascript
CVE-2023-46279 Vulnerability in maven package org.apache.dubbo:dubbo