Description
Jenkins RocketChat Notifier Plugin 1.5.2 and earlier stores the login password and webhook token unencrypted in its global configuration file on the Jenkins controller where they can be viewed by users with access to the Jenkins controller file system.
Remediation
References
https://www.jenkins.io/security/advisory/2022-06-30/#SECURITY-2088
Related Vulnerabilities
CVE-2021-41184 Vulnerability in maven package org.webjars.npm:jquery-ui
CVE-2020-2298 Vulnerability in maven package org.jenkins-ci.plugins:nerrvana-plugin
CVE-2021-21160 Vulnerability in maven package org.webjars.npm:electron
CVE-2018-11775 Vulnerability in maven package org.apache.activemq:activemq-client
CVE-2019-1003087 Vulnerability in maven package org.jenkins-ci.plugins:sinatra-chef-builder