Description
Jenkins TestQuality Updater Plugin 1.3 and earlier stores the TestQuality Updater password unencrypted in its global configuration file on the Jenkins controller where it can be viewed by users with access to the Jenkins controller file system.
Remediation
References
https://www.jenkins.io/security/advisory/2023-01-24/#SECURITY-2091
Related Vulnerabilities
CVE-2015-8858 Vulnerability in npm package uglify-js
CVE-2023-32990 Vulnerability in maven package org.jenkins-ci.plugins:azure-vm-agents
CVE-2019-1003031 Vulnerability in maven package org.jenkins-ci.plugins:matrix-project
CVE-2021-43859 Vulnerability in maven package com.thoughtworks.xstream:xstream
CVE-2019-17352 Vulnerability in maven package com.jfinal:jfinal