Description
Jenkins Katalon Plugin 1.0.32 and earlier stores API keys unencrypted in job config.xml files on the Jenkins controller where they can be viewed by users with Extended Read permission, or access to the Jenkins controller file system.
Remediation
References
http://www.openwall.com/lists/oss-security/2022/10/19/3
https://www.jenkins.io/security/advisory/2022-10-19/#SECURITY-2846
Related Vulnerabilities
CVE-2020-10968 Vulnerability in maven package com.fasterxml.jackson.core:jackson-databind
CVE-2020-2258 Vulnerability in maven package org.jenkins-ci.plugins:cloudbees-jenkins-advisor
CVE-2015-8854 Vulnerability in maven package org.webjars.npm:marked
CVE-2022-31195 Vulnerability in maven package org.dspace:dspace-api
CVE-2016-8749 Vulnerability in maven package org.apache.camel:camel-jackson