Description
Jenkins couchdb-statistics Plugin 0.3 and earlier stores its server password unencrypted in its global configuration file on the Jenkins controller where it can be viewed by users with access to the Jenkins controller file system.
Remediation
References
http://www.openwall.com/lists/oss-security/2020/10/08/5
https://www.jenkins.io/security/advisory/2020-10-08/#SECURITY-2065
Related Vulnerabilities
CVE-2022-43409 Vulnerability in maven package org.jenkins-ci.plugins.workflow:workflow-support
CVE-2021-40823 Vulnerability in npm package matrix-js-sdk
CVE-2019-19771 Vulnerability in npm package crytpo-js
CVE-2020-7786 Vulnerability in npm package macfromip
CVE-2020-28500 Vulnerability in maven package org.fujion.webjars:lodash