Description
Jenkins ElasTest Plugin 1.2.1 and earlier stores its server password unencrypted in its global configuration file on the Jenkins controller where it can be viewed by users with access to the Jenkins controller file system.
Remediation
References
http://www.openwall.com/lists/oss-security/2020/09/16/3
https://www.jenkins.io/security/advisory/2020-09-16/#SECURITY-2014
Related Vulnerabilities
CVE-2021-26275 Vulnerability in npm package eslint-fixer
CVE-2020-9296 Vulnerability in maven package com.netflix.conductor:conductor-core
CVE-2016-10599 Vulnerability in npm package sauce-connect
CVE-2023-37945 Vulnerability in maven package io.jenkins.plugins:miniorange-saml-sp
CVE-2020-12648 Vulnerability in maven package org.webjars.npm:tinymce