Description
Jenkins Elasticsearch Query Plugin 1.2 and earlier stores a password unencrypted in its global configuration file on the Jenkins controller where it can be viewed by users with access to the Jenkins controller file system.
Remediation
References
https://www.jenkins.io/security/advisory/2022-06-30/#SECURITY-2073
Related Vulnerabilities
CVE-2018-6874 Vulnerability in npm package auth0-js
CVE-2023-49376 Vulnerability in maven package com.jfinal:jfinal
CVE-2023-35150 Vulnerability in maven package org.xwiki.platform:xwiki-platform-invitation-ui
CVE-2023-24429 Vulnerability in maven package org.jenkins-ci.plugins:semantic-versioning-plugin
CVE-2023-22621 Vulnerability in npm package @strapi/plugin-users-permissions