Description
Jenkins Bumblebee HP ALM Plugin 4.1.5 and earlier stores credentials unencrypted in its global configuration file on the Jenkins controller where they can be viewed by users with access to the Jenkins controller file system.
Remediation
References
https://www.jenkins.io/security/advisory/2021-01-13/#SECURITY-2156
Related Vulnerabilities
CVE-2020-1718 Vulnerability in maven package org.keycloak:keycloak-parent
CVE-2018-1000013 Vulnerability in maven package org.jenkins-ci.plugins:release
CVE-2010-2273 Vulnerability in npm package dojo
CVE-2022-34198 Vulnerability in maven package org.jenkins-ci.plugins:stashbranchparameter
CVE-2012-3544 Vulnerability in maven package org.apache.tomcat:coyote