Description
Jenkins SMS Notification Plugin 1.2 and earlier stores an access token unencrypted in its global configuration file on the Jenkins controller where it can be viewed by users with access to the Jenkins controller file system.
Remediation
References
http://www.openwall.com/lists/oss-security/2020/10/08/5
https://www.jenkins.io/security/advisory/2020-10-08/#SECURITY-2054
Related Vulnerabilities
CVE-2020-7729 Vulnerability in maven package org.webjars.npm:grunt
CVE-2021-32622 Vulnerability in npm package matrix-react-sdk
CVE-2019-5457 Vulnerability in npm package min-http-server
CVE-2021-21292 Vulnerability in maven package org.traccar:traccar
CVE-2019-10352 Vulnerability in maven package org.jenkins-ci.main:jenkins-core