Description
Jenkins Bumblebee HP ALM Plugin 4.1.5 and earlier stores credentials unencrypted in its global configuration file on the Jenkins controller where they can be viewed by users with access to the Jenkins controller file system.
Remediation
References
https://www.jenkins.io/security/advisory/2021-01-13/#SECURITY-2156
Related Vulnerabilities
CVE-2021-45457 Vulnerability in maven package org.apache.kylin:kylin-server
CVE-2011-2092 Vulnerability in maven package com.adobe.blazeds:flex-messaging-core
CVE-2023-39152 Vulnerability in maven package org.jenkins-ci.plugins:gradle
CVE-2021-21672 Vulnerability in maven package org.jenkins-ci.plugins:seleniumhtmlreport
CVE-2022-34204 Vulnerability in maven package com.geteasyqa:easyqa