Description
Jenkins Squash TM Publisher (Squash4Jenkins) Plugin 1.0.0 and earlier stores passwords unencrypted in its global configuration file on the Jenkins controller where they can be viewed by users with access to the Jenkins controller file system.
Remediation
References
https://www.jenkins.io/security/advisory/2022-06-22/#SECURITY-2089
Related Vulnerabilities
CVE-2019-10277 Vulnerability in maven package hudson.plugins:starteam
CVE-2016-2166 Vulnerability in maven package org.apache.qpid:proton-j
CVE-2014-7810 Vulnerability in maven package org.apache.tomcat.embed:tomcat-embed-jasper
CVE-2023-36542 Vulnerability in maven package org.apache.nifi:nifi-dbcp-service
CVE-2019-3795 Vulnerability in maven package org.springframework.security:spring-security-core