Description
Jenkins SMS Notification Plugin 1.2 and earlier stores an access token unencrypted in its global configuration file on the Jenkins controller where it can be viewed by users with access to the Jenkins controller file system.
Remediation
References
http://www.openwall.com/lists/oss-security/2020/10/08/5
https://www.jenkins.io/security/advisory/2020-10-08/#SECURITY-2054
Related Vulnerabilities
CVE-2022-41704 Vulnerability in maven package org.apache.xmlgraphics:batik-bridge
CVE-2019-14862 Vulnerability in maven package org.webjars.npm:knockout
CVE-2023-0835 Vulnerability in npm package markdown-pdf
CVE-2023-27162 Vulnerability in maven package org.openapitools:openapi-generator-project
CVE-2023-34620 Vulnerability in maven package org.hjson:hjson