Description
Jenkins Convertigo Mobile Platform Plugin 1.1 and earlier stores passwords unencrypted in job config.xml files on the Jenkins controller where they can be viewed by users with Extended Read permission, or access to the Jenkins controller file system.
Remediation
References
https://www.jenkins.io/security/advisory/2022-06-22/#SECURITY-2064
Related Vulnerabilities
CVE-2023-27490 Vulnerability in npm package next-auth
CVE-2021-21118 Vulnerability in npm package electron
CVE-2019-12397 Vulnerability in maven package org.apache.ranger:ranger
CVE-2023-50730 Vulnerability in maven package org.typelevel:grackle-core_sjs1_2.13
CVE-2022-34778 Vulnerability in maven package org.jenkins-ci.plugins:testng-plugin