Description
Jenkins WSO2 Oauth Plugin 1.0 and earlier stores the WSO2 Oauth client secret unencrypted in the global config.xml file on the Jenkins controller where it can be viewed by users with access to the Jenkins controller file system.
Remediation
References
http://www.openwall.com/lists/oss-security/2023/04/13/3
https://www.jenkins.io/security/advisory/2023-04-12/#SECURITY-2992
Related Vulnerabilities
CVE-2019-25102 Vulnerability in npm package simple-markdown
CVE-2021-21179 Vulnerability in npm package electron
CVE-2023-27602 Vulnerability in maven package org.apache.linkis:linkis-storage-script-dev-server
CVE-2023-29032 Vulnerability in maven package org.apache.openmeetings:openmeetings-web
CVE-2022-46870 Vulnerability in maven package org.apache.zeppelin:zeppelin-web