Description
Jenkins SoapUI Pro Functional Testing Plugin 1.3 and earlier stores project passwords unencrypted in job config.xml files on the Jenkins controller where they can be viewed by attackers with Extended Read permission, or access to the Jenkins controller file system.
Remediation
References
http://www.openwall.com/lists/oss-security/2020/09/01/3
https://jenkins.io/security/advisory/2020-09-01/#SECURITY-1631%20%281%29
Related Vulnerabilities
CVE-2019-10787 Vulnerability in npm package im-resize
CVE-2020-28459 Vulnerability in npm package markdown-it-decorate
CVE-2020-28360 Vulnerability in npm package private-ip
CVE-2020-2196 Vulnerability in maven package org.jenkins-ci.plugins:selenium
CVE-2019-10347 Vulnerability in maven package javagh.jenkins:mashup-portlets-plugin