Description
Jenkins Build Notifications Plugin 1.5.0 and earlier stores tokens unencrypted in its global configuration files on the Jenkins controller where they can be viewed by users with access to the Jenkins controller file system.
Remediation
References
https://www.jenkins.io/security/advisory/2022-06-30/#SECURITY-2056
Related Vulnerabilities
CVE-2022-25206 Vulnerability in maven package org.jenkins-ci.plugins:dbcharts
CVE-2019-10432 Vulnerability in maven package org.jenkins-ci.plugins:htmlpublisher
CVE-2023-30513 Vulnerability in maven package org.csanchez.jenkins.plugins:kubernetes
CVE-2020-17531 Vulnerability in maven package org.apache.tapestry:tapestry-core
CVE-2017-1000354 Vulnerability in maven package org.jenkins-ci.main:jenkins-core